{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b775b5b1-c63d-5620-8953-e481d776d8f4",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/cryptography@42.0.8.post1+tuxcare",
      "type": "library",
      "name": "cryptography",
      "version": "42.0.8.post1+tuxcare",
      "purl": "pkg:pypi/cryptography@42.0.8.post1+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2e8de730-2d29-5081-82d7-fa98246e8466",
      "id": "CVE-2024-12797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-12797 is fixed in version 42.0.8.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@42.0.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cf85982-8206-5647-ae69-af58486b0661",
      "id": "CVE-2026-26007",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-26007 affects version 42.0.8.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@42.0.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba370924-504c-5067-a6d4-f6646938200d",
      "id": "CVE-2026-34073",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34073 affects version 42.0.8.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@42.0.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05618e85-1113-547c-a655-81eef340821d",
      "id": "CVE-2026-69248",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-69248 does not affect version 42.0.8.post1+tuxcare of cryptography. not_affected \u2014 Target version 42.0.8.post2+tuxcare is NOT affected by CVE-2026-69248. The vulnerability requires wildcard DNS SAN support in name constraint validation, which was introduced in upstream commit 286c89128 (Jan 7, 2025) and fixed in commit 91d728897 (Mar 25, 2026, also known as CVE-2026-34073). The 42.x branch never received the vulnerable wildcard support code. Instead, this version uses the old..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@42.0.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccd4d562-abe2-54fc-9a8a-fa35b55fcea5",
      "id": "CVE-2026-69249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69249 affects version 42.0.8.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@42.0.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51741a0b-e33c-5341-9b29-4e9876ab916f",
      "id": "GHSA-537c-gmf6-5ccf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-537c-gmf6-5ccf affects version 42.0.8.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@42.0.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18a0d747-71da-5acd-bd27-835045acc413",
      "id": "GHSA-h4gh-qq45-vh27",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-h4gh-qq45-vh27 is fixed in version 42.0.8.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@42.0.8.post1+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/cryptography@42.0.8.post1+tuxcare"
    }
  ]
}