{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4294d1ed-6453-56dd-aa7d-db24b42b3dea",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "pillow",
      "purl": "pkg:pypi/pillow@8.4.0.post6+tuxcare",
      "type": "library",
      "bom-ref": "pkg:pypi/pillow@8.4.0.post6+tuxcare",
      "version": "8.4.0.post6+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2022-22815",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:c500d5e1-4e17-58f7-b125-59e164ab100b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22815 is fixed in version 8.4.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2022-22816",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:3269c31f-4e48-5db1-9867-a87387812790",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22816 is fixed in version 8.4.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2022-22817",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:59ed8129-92c4-53a5-baea-eae13debfad2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22817 is fixed in version 8.4.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2022-45198",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:bbad34a8-7a3e-5b63-89b0-0a646aea0a81",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45198 is fixed in version 8.4.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2023-4863",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:18c0ffd9-1747-5eda-836e-470244d48d65",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-4863 does not affect version 8.4.0.post6+tuxcare of pillow. not_affected \u2014 CVE-2023-4863 is a heap buffer overflow vulnerability in libwebp's huffman_utils.c (BuildHuffmanTable function). Pillow 8.4.0 does not contain libwebp source code - it only has build scripts (install_webp.sh) that specify libwebp-1.2.1 as an external dependency to download and link. The vulnerable code lives in the separate libwebp repository, not in Pillow's codebase. Per the DOC-ONLY PATCH ru...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2023-50447",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:37610424-84ba-5c10-bfe3-b5e65a672ba2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50447 is fixed in version 8.4.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2024-28219",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:2ca35b3e-9b15-57a1-94e7-21ab4c0b7069",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28219 is fixed in version 8.4.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-42308",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:acb705fd-5861-58a8-bfbb-921ed24de754",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 8.4.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-42310",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4a0b2349-97d2-5bff-820f-7fdaa52100ae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 8.4.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-54059",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:93a5ed2c-dc4d-5620-9c92-13d74a6288e5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 8.4.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-54060",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:52f8e4aa-daa5-5b48-bfcf-080e9e35c2b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54060 is fixed in version 8.4.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-55379",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e37ed3e4-844d-50b3-a221-15b34ec4ec5f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 8.4.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-55380",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:63a8eaa5-71b1-5a1b-b0a8-6126fc44a578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 8.4.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-55798",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:8e0bbe7d-1945-5d6e-8c90-f413972cbd4b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55798 is fixed in version 8.4.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59197",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:f7e9f372-9c6f-5583-a1c9-43cf33a5d8f8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 8.4.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59198",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:bc35d71f-8011-54d4-8a36-82964a58719a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 8.4.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59199",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:772e3a88-bd73-524c-b650-e54d0f80bba1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 8.4.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59200",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:1d5e3e92-ccd0-5245-86f3-cae2c2391bee",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 8.4.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59204",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:00ed7489-0248-5c59-a478-c17a5977cdb2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 8.4.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59205",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:23066668-aa7c-5f36-96cf-be6882da9102",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 8.4.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "GHSA-4fx9-vc88-q2xc",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:52925304-5abe-52fa-8ce2-48aa2bd5f870",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4fx9-vc88-q2xc is fixed in version 8.4.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "GHSA-56pw-mpj4-fxww",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:9e773da8-f468-5b2e-9f15-d04bd505e335",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-56pw-mpj4-fxww is a false positive for pillow 8.4.0.post6+tuxcare."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
    }
  ]
}