{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:285e81a2-bf36-5add-9734-cf9e36eb482b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
      "type": "library",
      "name": "pypdf",
      "version": "5.9.0.post2+tuxcare",
      "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:bbc09aaa-d622-52b3-9d17-faefa341de7d",
      "id": "CVE-2025-55197",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5223778b-c91a-5d00-a3ed-02341ff8db08",
      "id": "CVE-2025-62707",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4aef023-1fdc-5356-942a-03ede0445b26",
      "id": "CVE-2025-62708",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-62708 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a90b8e40-6426-506c-a852-e74ad5b430d6",
      "id": "CVE-2025-66019",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66019 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1c26ff8-4902-507e-a46e-d791399376a9",
      "id": "CVE-2026-22690",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22690 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13631f30-da95-594c-92ed-adb44fade09b",
      "id": "CVE-2026-22691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22691 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:285582ab-9537-5bfe-92f9-379da24a3611",
      "id": "CVE-2026-24688",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24688 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7a65dd1-fd78-5e7e-acfd-83e4337c2fee",
      "id": "CVE-2026-27024",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27024 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1322d25-0c6b-549b-b1c3-85a7b0482229",
      "id": "CVE-2026-27025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27025 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a657ec0-8eff-5ac0-a5dd-fdd1e8ae81bd",
      "id": "CVE-2026-27026",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27026 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3a86814-ac0c-5ba8-b2ac-2a92ea3205b9",
      "id": "CVE-2026-27628",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27628 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e33b2984-7c66-54c3-9646-2c7e9ad3d7b8",
      "id": "CVE-2026-27888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27888 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3aca3b7b-a58f-58ad-9069-c2b10aa315f8",
      "id": "CVE-2026-28351",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28351 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b12c9bd7-ba14-536c-8f82-6e71b19df3f6",
      "id": "CVE-2026-28804",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28804 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6719b708-52fc-5b05-b210-283fb6335a66",
      "id": "CVE-2026-31826",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31826 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea663bf1-fbd1-5871-8951-5f3254903a33",
      "id": "CVE-2026-33123",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33123 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:771b343e-1c38-5689-af8c-b6702404702a",
      "id": "CVE-2026-33699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33699 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cf0734b-8134-5fc4-b95b-22b7d8bad280",
      "id": "CVE-2026-40260",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40260 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66aed09a-1c91-55cd-8323-b527cfc6f2ca",
      "id": "CVE-2026-41168",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41168 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57085391-a59a-5d8d-ac55-96ce810d0e20",
      "id": "CVE-2026-41312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41312 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77748d78-1a22-584f-8508-52bf6533c0fa",
      "id": "CVE-2026-41313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41313 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea6157af-72e9-5ede-9cea-5d8e2deb8016",
      "id": "CVE-2026-41314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41314 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df38fb41-52b9-52f8-8d0d-4e968fded98d",
      "id": "CVE-2026-48155",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48155 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a98dacd-a1e8-55b7-a172-a575fc4e2daf",
      "id": "CVE-2026-48156",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48156 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab3bcb28-5600-5877-ab2c-74bd02b49f39",
      "id": "CVE-2026-48735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48735 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdcafc89-9aa0-5f00-95df-88d9f29be8da",
      "id": "CVE-2026-49460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49460 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:607bffe6-b136-5dc6-8ec3-c271ab282cfe",
      "id": "CVE-2026-49461",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49461 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b45288cc-25b9-5852-93ce-6c605b1906e5",
      "id": "CVE-2026-54530",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54530 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad96fc7c-c28f-5e9b-a4bd-9c398b48087d",
      "id": "CVE-2026-54531",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54531 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:083dacdd-3cfd-5db2-98f4-529548a4ba93",
      "id": "CVE-2026-54651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54651 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9055e24-19b6-5946-a634-27306c8e80dc",
      "id": "CVE-2026-59935",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59935 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37754617-b42c-5a37-a83f-e67f1ce763ba",
      "id": "CVE-2026-59936",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59936 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d744651f-2e8c-5cf9-b3d4-abdbef4817ed",
      "id": "CVE-2026-59937",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59937 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab93f720-8a2b-53bf-9acd-8448ef77f25e",
      "id": "CVE-2026-59938",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59938 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d43c71e0-c997-5949-bba5-690651823f6f",
      "id": "GHSA-4pxv-j86v-mhcw",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c7426d9-e8ac-57c9-b704-5d7b3c9ae15f",
      "id": "GHSA-7gw9-cf7v-778f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e011c833-4f08-5515-adba-17802e43e993",
      "id": "GHSA-9m86-7pmv-2852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aada6d10-9ab2-5919-b159-7c21b5f2b493",
      "id": "GHSA-jj6c-8h6c-hppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca13d0b7-cc5e-5d70-b1cc-b4aa39844596",
      "id": "GHSA-jm82-fx9c-mx94",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5169f07a-5e7c-5824-94b0-1da8b7fe2c61",
      "id": "GHSA-x284-j5p8-9c5p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
    }
  ]
}