{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ed4c7f40-acb0-5341-9858-0bae59a45913",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/django@4.0.post14+tuxcare",
      "type": "library",
      "name": "django",
      "version": "4.0.post14+tuxcare",
      "purl": "pkg:pypi/django@4.0.post14+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d49a2650-6c14-5616-b608-a0cc76789569",
      "id": "CVE-2021-45115",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f2704bc-f47c-5943-b36b-03a792a2617b",
      "id": "CVE-2021-45116",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e460b9f3-70d5-59ff-bf54-ce513d468af9",
      "id": "CVE-2021-45452",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03320efe-1268-5b63-863a-3c6843e26e64",
      "id": "CVE-2022-22818",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b4fbde7-5fd8-5a23-ab80-b0d6db04adf3",
      "id": "CVE-2022-23833",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23833 is fixed in version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92b92492-369f-5633-b841-fc6af26822d9",
      "id": "CVE-2022-28346",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2a8934f-f608-59bf-a8ab-c9158eab261c",
      "id": "CVE-2022-28347",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12e828bc-4b76-5205-a7de-140c4adae3a6",
      "id": "CVE-2022-34265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a4b1633-465c-5012-a002-98a648cc126b",
      "id": "CVE-2022-36359",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9fcddc4-4a37-57aa-9fbb-ac54a48c36ed",
      "id": "CVE-2022-41323",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f468a6e6-5d18-5ec1-9bd3-4445725b0c3b",
      "id": "CVE-2023-23969",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82e85d7c-640a-5e8f-8456-772b74efde04",
      "id": "CVE-2023-24580",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:450567f6-502f-5702-941c-f288ccdb5557",
      "id": "CVE-2023-31047",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-31047 is fixed in version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8518def4-8aa8-5838-bf35-9c5a178b08d2",
      "id": "CVE-2023-36053",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-36053 is fixed in version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:feef7270-fc60-5e01-a778-067837941f4a",
      "id": "CVE-2023-43665",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-43665 is fixed in version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55d46123-f002-55f5-bf9c-8249b2b9318c",
      "id": "CVE-2023-46695",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46695 affects version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4d2b421-668e-5f5e-b4f1-7abac991be9c",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45231 affects version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b62be68d-9f03-57d5-88e3-b72fbc35f5ac",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:690acff7-561d-56ea-a930-e26c936856ea",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4163cc09-6f5d-52ab-9bc5-2759ec86fe94",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14550 is fixed in version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60991364-f82e-58dc-9fcd-c9750980da1f",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9651e6df-3161-590f-b98f-766306edfb69",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52bdadad-476f-5ccc-98d4-fda6ec74c7d2",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64458 is fixed in version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da719071-ef98-5f90-8c09-b8e14c3893e9",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64459 is fixed in version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e030009-f47a-5ab2-8fe4-38f2a7998144",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64460 is fixed in version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41f4a42f-ef8e-5e7e-ab4c-b8be51644c38",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1207 is fixed in version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e127e8be-9fb2-5e46-b933-174590266f01",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57ab5933-9e80-5893-aaee-33953a155395",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0d10d05-4627-5e24-84b5-94fbe95fc409",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1312 is fixed in version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:009fcbef-b33a-58eb-b8d3-3677f42d863c",
      "id": "CVE-2026-48587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48587 affects version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76258ccf-110c-598c-a40d-ec808e15e44b",
      "id": "CVE-2026-48588",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48588 affects version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:faa855e6-817c-5645-bf29-ec65326bb7cb",
      "id": "CVE-2026-53877",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53877 affects version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f38a565-9e2e-5da9-b8e8-fb4c2b8bf08d",
      "id": "CVE-2026-53878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-53878 does not affect version 4.0.post14+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a948ed73-4494-526b-98a2-89e2caa74fc6",
      "id": "CVE-2026-6873",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6873 affects version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08edf727-6f0f-5387-bdb8-9ca4a3b3c872",
      "id": "CVE-2026-8404",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-8404 affects version 4.0.post14+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post14+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/django@4.0.post14+tuxcare"
    }
  ]
}