{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:21bc0ba9-b6c8-585e-913c-096a5fe87a46",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/django@5.0.1.post2+tuxcare",
      "type": "library",
      "name": "django",
      "version": "5.0.1.post2+tuxcare",
      "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7e6bc725-d88a-5985-865d-fb4c4d165402",
      "id": "CVE-2024-24680",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-24680 is fixed in version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0139a248-0a3d-506b-b727-6dabfc77ca79",
      "id": "CVE-2024-27351",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27351 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07ea92c3-3b82-5b56-85cf-1cb0ab2b9842",
      "id": "CVE-2024-38875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38875 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06464612-f997-5f23-bf03-747ea32ddbb9",
      "id": "CVE-2024-39329",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39329 is fixed in version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58b6bd33-7bec-5baf-a236-177c833d2c45",
      "id": "CVE-2024-39330",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39330 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fde25b4-8de1-5bd1-885b-9d754d01aaf4",
      "id": "CVE-2024-39614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39614 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfa4f26f-39cb-5e54-8823-156332348a08",
      "id": "CVE-2024-41989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-41989 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbe87fd8-8f69-5ec1-acb6-3889d6336dee",
      "id": "CVE-2024-41990",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-41990 does not affect version 5.0.1.post2+tuxcare of django. not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7989c9d9-164f-55da-a460-1aa845f1a8b8",
      "id": "CVE-2024-41991",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-41991 is fixed in version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06fc9401-7fca-51f9-981d-391a0588701b",
      "id": "CVE-2024-42005",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-42005 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51cb02ec-308e-5643-8d2e-3a9d2121eab7",
      "id": "CVE-2024-45230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45230 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40b4bc44-f990-5e7b-a4ee-ef5baf0d2b1f",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45231 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a19ef7eb-a1cc-5413-ac27-883d4dad7e56",
      "id": "CVE-2024-53907",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-53907 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21f6d873-5670-558c-a277-fd2a760ced27",
      "id": "CVE-2024-53908",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-53908 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b40f062-e03e-5396-92d9-80d5355ec6a7",
      "id": "CVE-2024-56374",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56374 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bbe902b-0e82-5552-b358-9affc72bb648",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d98ba4a2-21a4-51bf-ba3d-6896a72376a3",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:171b3e12-6d9a-5630-b01d-52bad5c537e9",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63215615-49c6-5125-89b6-8f91797b55f5",
      "id": "CVE-2025-26699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-26699 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:684ff4a2-7eeb-57fe-87e9-56a0a5c9453f",
      "id": "CVE-2025-27556",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27556 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e3944b7-e762-5e72-975c-f43d13ca0ec5",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e67b853-c075-53af-9e14-138cae240dc5",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3984632-21b7-52fa-a6b6-5ab512f2c06a",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72877962-a2de-5598-9962-53c5a07ca027",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64459 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61bb6da9-6207-5161-936f-936faaac9017",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cd02e56-9a25-5902-985a-3c013ea1cc6a",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6cce08b-d540-568a-ad91-ab2f6c8ccb68",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6fc8015-c0b4-5f22-a556-46e51e103c36",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e9a9a29-7e23-52a5-b218-7ccaa4554125",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5888c09d-6bc2-57d8-a7de-911992c89453",
      "id": "CVE-2026-48587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48587 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72375294-437a-5375-9449-24dea34e8abb",
      "id": "CVE-2026-48588",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48588 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c775f5d-0fcd-5ec4-b06b-c75590177063",
      "id": "CVE-2026-53877",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53877 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c51f8223-5fc1-5ba4-9137-ca14988abcf2",
      "id": "CVE-2026-53878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-53878 does not affect version 5.0.1.post2+tuxcare of django. not_affected \u2014 Django 5.0.1 is not affected by CVE-2026-53878. The CVE describes a vulnerability in the DomainNameValidator class introduced in Django 5.1, where regex patterns without proper anchors allowed domains containing newlines to pass validation. Django 5.0.1 does not have this class. All domain validation mechanisms in 5.0.1 (_simple_domain_name_validator, EmailValidator.domain_regex, URLValidator.u..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6ca97d8-a396-5d60-a56d-574aca7b071a",
      "id": "CVE-2026-6873",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6873 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33d921df-6dda-57cc-8e7f-63df5c741201",
      "id": "CVE-2026-8404",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-8404 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
    }
  ]
}