{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fa9d4b19-f40c-5cf6-9eef-daf4d5578dfe",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "11.3.0.post1+tuxcare",
      "purl": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:3aae28cc-cc98-5610-9b02-90fd6e059dae",
      "id": "CVE-2026-25990",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25990 is fixed in version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01685bc6-4dad-5df7-aafe-f40c8eca88c4",
      "id": "CVE-2026-40192",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40192 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:733ac214-b8d0-5e1e-962f-7996b82d8ad9",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8c3c875-51be-5eb6-a7e4-2be2871cc699",
      "id": "CVE-2026-42309",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42309 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b47a89d3-07b5-5d9b-88d6-2f7dadbff0bc",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5a41ab3-f46e-51af-8874-17ca3d7ca1ce",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54058 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c69a0ff-c614-5df2-8123-a7761e631b91",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cea215f-e1e6-5174-a0df-7e72734eda38",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54060 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2302ae8-5160-5495-af37-0731d78a4c3b",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:493689b7-dd81-55bf-b213-cc6db3427aaf",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1443eb34-47de-5b6a-bc2a-2f3c7af6b39a",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55798 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab977522-6157-5310-8928-316aa2c9dddd",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a706c54d-e03a-5b3c-bb38-a60516d418b1",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc8a15c2-6ea0-5296-8272-bddf046ecc46",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58c9d11b-3ce6-5d28-845f-bbab42605451",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e6254ed-9da5-52c8-9a1f-bed59310cf1a",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f767638d-7cf2-522e-8d01-806cfe1be327",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
    }
  ]
}