{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:565ed35f-688f-5484-9fad-39e15664293d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/django@4.2.post9+tuxcare",
      "type": "library",
      "name": "django",
      "version": "4.2.post9+tuxcare",
      "purl": "pkg:pypi/django@4.2.post9+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d98ad36f-144b-54e3-ae01-4e9dec6a165a",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13372 is fixed in version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3ea2667-b7fc-55ab-8b43-ba47fed2331f",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13473 is fixed in version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:697b7ac5-39ec-5e85-b638-3b8ff3e5463b",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14550 is fixed in version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39dade8d-b776-5fac-85a2-2bb2d1417b4b",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48432 is fixed in version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3772635b-11d8-5ec0-b9ef-0fd2041905f0",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a89b5599-7da7-52e3-92c6-5fc34cad22c4",
      "id": "CVE-2025-59681",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59681 is fixed in version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fed14fc6-8387-5c58-9e5d-66d4d039d40d",
      "id": "CVE-2025-59682",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59682 is fixed in version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0978f917-d539-59ad-ac1b-6f2ce12e21ec",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64458 is fixed in version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcab2b48-71c2-5218-af01-4f32b0de7d34",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64459 is fixed in version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d937b5c-67e8-5054-9d22-4a9d3d1924d7",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64460 is fixed in version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e99efb55-5e0d-5423-ac43-3f6197489f75",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1207 is fixed in version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5891c977-ca96-50a1-b4c7-0593f203bc69",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1285 is fixed in version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f263c1f7-9655-50cf-b410-115f238aaca6",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4635af6c-f462-50c5-b43e-aaf09793460c",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1312 is fixed in version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad8b1a66-06ce-57f0-a921-2457919ccbda",
      "id": "CVE-2026-25673",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25673 is fixed in version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ba7bcfc-553d-5e01-94f5-65692e045625",
      "id": "CVE-2026-25674",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25674 is fixed in version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0c4ebbe-aa90-5933-8892-855e069767bb",
      "id": "CVE-2026-33033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33033 is fixed in version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2f8d524-e3c7-5639-9619-54abd0c9688e",
      "id": "CVE-2026-33034",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33034 is fixed in version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:159d6119-900d-55dc-a1d3-6083d9dc82e6",
      "id": "CVE-2026-3902",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-3902 is fixed in version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63719e5f-2669-5375-a551-e946abd54b2d",
      "id": "CVE-2026-4277",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4277 is fixed in version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d549c17e-0726-5b55-96d6-13580509fe46",
      "id": "CVE-2026-4292",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4292 is fixed in version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:418c7c4f-0204-596a-9517-da30003f16bf",
      "id": "CVE-2026-48587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48587 affects version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ea6d03c-cda8-5340-ba36-43f0cc659dd0",
      "id": "CVE-2026-48588",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48588 affects version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82a7d5ca-700b-5846-95e3-9d7cd3d36275",
      "id": "CVE-2026-53877",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53877 affects version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24e9c27d-b3de-550b-a702-d0ccdf65e0ba",
      "id": "CVE-2026-53878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-53878 does not affect version 4.2.post9+tuxcare of django. not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3dcbd2c-6208-54a4-bd64-cf7095e5102a",
      "id": "CVE-2026-6873",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6873 affects version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ee79dcb-d7ac-581e-833c-80c470c7baea",
      "id": "CVE-2026-8404",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-8404 affects version 4.2.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post9+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/django@4.2.post9+tuxcare"
    }
  ]
}