{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:722eb915-b04d-539b-ab4d-4ff3f3990468",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/django@5.1.10.post1+tuxcare",
      "type": "library",
      "name": "django",
      "version": "5.1.10.post1+tuxcare",
      "purl": "pkg:pypi/django@5.1.10.post1+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0b3f6046-0b63-59a2-ba48-6c4a647440ba",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 5.1.10.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.10.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f27ba979-985b-5619-87d2-2e9fa2244c5c",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 5.1.10.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.10.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ccfd792-c90a-5f8e-ba5a-fb3177443fa3",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 5.1.10.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.10.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd74286c-948d-522f-8b1d-7db675d0f1df",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 5.1.10.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.10.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97920e77-2daa-5a89-925f-7be58afbe75b",
      "id": "CVE-2025-59681",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59681 affects version 5.1.10.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.10.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c30739a7-e040-54f1-ba23-55b2007700b1",
      "id": "CVE-2025-59682",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59682 affects version 5.1.10.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.10.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cdf7087-9255-5349-ae8c-b19e9524cfd0",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 5.1.10.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.10.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7920543-75e7-5006-b842-2c20f16ecd44",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64459 is fixed in version 5.1.10.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.10.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97387fb6-e027-544d-9a60-f04ad13e3265",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 5.1.10.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.10.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce994d69-94b6-53d7-b9d9-98303cf91b4d",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 5.1.10.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.10.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c13c4e98-dac9-5fc2-8936-5459c4457a43",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 5.1.10.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.10.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfaf8db6-e334-5803-93fe-9e2df7634a25",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 5.1.10.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.10.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f573b7e-7ccd-5497-94a0-ee993a46fc49",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 5.1.10.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.10.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bdd7b45-b5af-5239-b60e-402b46e65be6",
      "id": "CVE-2026-48587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48587 affects version 5.1.10.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.10.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:406f14a7-a376-512f-9672-4152d000ae8c",
      "id": "CVE-2026-48588",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48588 affects version 5.1.10.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.10.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fb83881-a8b7-5a03-a278-b14d8ef7f1d3",
      "id": "CVE-2026-53877",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53877 affects version 5.1.10.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.10.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f40cce3-83df-5ae7-8887-02c6d6364c0a",
      "id": "CVE-2026-53878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-53878 does not affect version 5.1.10.post1+tuxcare of django. not_affected \u2014 Django 5.1.10 is not affected by CVE-2026-53878. While DomainNameValidator does accept domain names with trailing newlines (due to Python regex '$' matching before newlines), Django itself is protected by HttpResponse's runtime newline checks. All HTTP responses in Django go through ResponseHeaders._convert_to_charset() which explicitly checks for and rejects '\\n' and '\\r' characters in header ..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.10.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fc73822-705a-51d5-b6f7-ef5d2c8fb7df",
      "id": "CVE-2026-6873",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6873 affects version 5.1.10.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.10.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc52031b-34e3-599e-9f09-d48f05bd355a",
      "id": "CVE-2026-8404",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-8404 affects version 5.1.10.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.10.post1+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/django@5.1.10.post1+tuxcare"
    }
  ]
}