{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8f749c50-874d-5ea5-9b2f-8e958aeab134",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/cryptography@41.0.7.post1+tuxcare",
      "type": "library",
      "name": "cryptography",
      "version": "41.0.7.post1+tuxcare",
      "purl": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6a80f03a-5fce-5984-acd9-77ff9f430a0a",
      "id": "CVE-2023-50782",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50782 is fixed in version 41.0.7.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6e9156b-c6a4-592d-8ce4-781809c72340",
      "id": "CVE-2024-0727",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-0727 affects version 41.0.7.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e33662f7-0062-519a-8ca6-24237633fb9e",
      "id": "CVE-2024-26130",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-26130 is fixed in version 41.0.7.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e0eb505-1d43-5496-8065-f95ed20af2c4",
      "id": "CVE-2026-26007",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-26007 affects version 41.0.7.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23c9577f-ddb8-53de-90e4-9ca6c282eb43",
      "id": "CVE-2026-34073",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34073 affects version 41.0.7.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdb3b949-86b2-5b60-ad8c-f27525823881",
      "id": "CVE-2026-69248",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-69248 does not affect version 41.0.7.post1+tuxcare of cryptography. not_affected \u2014 python-cryptography version 41.0.7.post2+tuxcare is NOT AFFECTED by CVE-2026-69248. The vulnerability exists in the x509 verification module's DNS name constraint matching logic when validating wildcard SANs against intermediate CA constraints. However, the entire x509.verification module (including PolicyBuilder, Store, build_server_verifier, and the Rust cryptography-x509-verification compone..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f94b1b19-fc23-5bd9-be78-9923e554af45",
      "id": "CVE-2026-69249",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-69249 does not affect version 41.0.7.post1+tuxcare of cryptography. not_affected \u2014 Version 41.0.7 is not affected by CVE-2026-69249. The vulnerable x509.verification module with its build_chain_inner function was introduced in cryptography version 42.0.0. Version 41.0.7 predates this feature and has no certificate chain validation API exposed to users. The INPUT type (certificate chains passed to PolicyBuilder.verify()) cannot be received in this version because the entire ve..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99f004b1-6c55-5097-afbd-4d02cd07e09d",
      "id": "GHSA-537c-gmf6-5ccf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-537c-gmf6-5ccf affects version 41.0.7.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76395333-512d-5815-adac-360cf5ed6d90",
      "id": "GHSA-h4gh-qq45-vh27",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-h4gh-qq45-vh27 affects version 41.0.7.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
    }
  ]
}