{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0d0f5d87-b17e-5659-95ec-0bb78ab5325f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "11.3.0.post2+tuxcare",
      "purl": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6d6beb4b-fc1e-5a68-875a-cd87af2acec8",
      "id": "CVE-2026-25990",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25990 is fixed in version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d66cac93-23e3-5075-a739-f7c6b0024769",
      "id": "CVE-2026-40192",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40192 is fixed in version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc266347-4f74-557d-a4c7-39403ade570a",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c005d3c4-aeff-5404-a1df-c7bbdf1de2ea",
      "id": "CVE-2026-42309",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42309 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36fe5647-2a86-5b98-b4c3-49e9aa220b2d",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fc1a4a6-791b-51df-bb91-3c56d65196fa",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54058 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:924b5982-d46f-56fa-9c01-b70fd75126ab",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bf89f4e-690e-5565-a36c-4aef5ce0afef",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54060 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98395d1f-2f64-5459-8626-fa6069d426b5",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:435144bf-d799-587f-a761-c318319c8060",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de9cc2b7-4695-5403-8aa6-d75c0387d13d",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55798 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44f97682-8d54-5aea-8d02-a12c1216c162",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6c46ae5-9bd8-505f-b6fc-aab0c651af4c",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68f9c47e-6eee-5d7b-b1f8-80714bea699d",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5402b0af-eb0d-5cca-8d0b-22a37065aed8",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:645a749d-957b-583e-a958-cd0f7a0676a7",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d574f4fe-a4c9-5390-8ee3-7d2c02fa6aef",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
    }
  ]
}