{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5d5057ee-b7c4-5641-b13e-f2c21b0a11df",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
      "type": "library",
      "name": "pypdf",
      "version": "5.9.0.post3+tuxcare",
      "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ec68fa48-14ee-5cae-b04a-06dd5379310d",
      "id": "CVE-2025-55197",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5650a7e-1ae8-5dc1-8b14-4da721d84944",
      "id": "CVE-2025-62707",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58f103c2-184f-53c2-998c-8a6c812e778d",
      "id": "CVE-2025-62708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbaaecda-f855-509d-9b8d-76f79c5a9377",
      "id": "CVE-2025-66019",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66019 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca626369-d5b4-5e67-bc59-1d02a2bdb3f3",
      "id": "CVE-2026-22690",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22690 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7d17593-675b-5ecc-b3fa-3843ed83a8f2",
      "id": "CVE-2026-22691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22691 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ef45a19-97d7-540f-9eef-5b98145fbd3e",
      "id": "CVE-2026-24688",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24688 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc63fe09-1358-5de2-8e95-839ce32c7fc0",
      "id": "CVE-2026-27024",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27024 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dca30031-7074-517a-8d4c-640b7ff94197",
      "id": "CVE-2026-27025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27025 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fde69527-c36b-575c-a479-8478611d6c8f",
      "id": "CVE-2026-27026",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27026 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82a0bc37-11c9-5e49-bb4c-d3eb23531cc6",
      "id": "CVE-2026-27628",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27628 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:486d76ad-71f4-592f-8f0b-c07dc93c1644",
      "id": "CVE-2026-27888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27888 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4d0290e-a144-5179-9051-d6a9a69a69a5",
      "id": "CVE-2026-28351",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28351 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ace374b-cf4c-5099-b1cc-9b37d1be7747",
      "id": "CVE-2026-28804",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28804 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1341f2da-2c9b-531a-be16-888d2ae92b44",
      "id": "CVE-2026-31826",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31826 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4e2b8ce-6193-5f53-8307-aaea5ac937a1",
      "id": "CVE-2026-33123",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33123 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32e9ba15-11c4-5c65-9209-4985544211e4",
      "id": "CVE-2026-33699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33699 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea928941-f0ba-5ebb-81ec-38e857c0f740",
      "id": "CVE-2026-40260",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40260 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e11297dc-2613-5f56-8e54-97ad4fe47908",
      "id": "CVE-2026-41168",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41168 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:084b1f7e-9d50-591e-9b43-a33b8ff789b0",
      "id": "CVE-2026-41312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41312 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb01faf7-bd75-5693-b979-9f77da5ff8a8",
      "id": "CVE-2026-41313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41313 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5f3ba5b-653a-50b1-90d2-d8ceabe7cdb6",
      "id": "CVE-2026-41314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41314 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66bd27d8-349c-592f-9ebe-fa6684a35308",
      "id": "CVE-2026-48155",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48155 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b081c9e-9a03-55b0-9ca9-ef8390339ed8",
      "id": "CVE-2026-48156",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48156 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5752a9ad-1b3b-588c-9051-ae2f27fff56e",
      "id": "CVE-2026-48735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48735 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb950a37-8d3a-5f37-bec4-9a398a714436",
      "id": "CVE-2026-49460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49460 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7618faee-ff86-5ac5-99b6-997270007304",
      "id": "CVE-2026-49461",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49461 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ee81747-f104-5bfc-b6df-1008e360e26c",
      "id": "CVE-2026-54530",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54530 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83513cd2-1d8d-5bea-b32e-912fea23dfd5",
      "id": "CVE-2026-54531",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54531 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:077b226e-f716-59fa-9fca-10a0f313cfdb",
      "id": "CVE-2026-54651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54651 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d955b3f9-ba36-5fa1-b28c-1b020cd8ea65",
      "id": "CVE-2026-59935",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59935 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f89506dd-60fc-50c8-ba36-d7413c46e673",
      "id": "CVE-2026-59936",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59936 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34c8f516-35eb-5c48-9ca6-21984cffa506",
      "id": "CVE-2026-59937",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59937 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d5af52d-5de2-5b50-8b94-988e9f31e51e",
      "id": "CVE-2026-59938",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59938 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2c3f964-09b6-5df8-bf55-baee19c68db3",
      "id": "GHSA-4pxv-j86v-mhcw",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:692e2e55-429f-58c4-b53b-1448b6fb7e49",
      "id": "GHSA-7gw9-cf7v-778f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1535f64-8bc1-5ef7-ac63-3a560e0a6146",
      "id": "GHSA-9m86-7pmv-2852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58c8d490-011c-5cc2-b423-7efcb185b893",
      "id": "GHSA-jj6c-8h6c-hppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2103984e-5e6f-5db8-9d5d-ec1fc6747b20",
      "id": "GHSA-jm82-fx9c-mx94",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f04991e-f313-569c-a623-7b1c5104fa4e",
      "id": "GHSA-x284-j5p8-9c5p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
    }
  ]
}