{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4528337a-fba4-5116-bb1f-c530072766a8",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "pillow",
      "purl": "pkg:pypi/pillow@8.4.0.post7+tuxcare",
      "type": "library",
      "bom-ref": "pkg:pypi/pillow@8.4.0.post7+tuxcare",
      "version": "8.4.0.post7+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2022-22815",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:a47ae00a-3849-5d3e-b198-74af42812d24",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22815 is fixed in version 8.4.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2022-22816",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:876bf499-9093-53a2-9bb3-878f41c7a10f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22816 is fixed in version 8.4.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2022-22817",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4cc50b94-01c4-554b-af23-3757a49dc86f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22817 is fixed in version 8.4.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2022-45198",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:32695904-9b51-5078-901d-ae6a3c235b5f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45198 is fixed in version 8.4.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2023-4863",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:5ef6cd12-7561-54a7-aba1-4cfe890e9257",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-4863 does not affect version 8.4.0.post7+tuxcare of pillow. not_affected \u2014 CVE-2023-4863 is a heap buffer overflow vulnerability in libwebp's huffman_utils.c (BuildHuffmanTable function). Pillow 8.4.0 does not contain libwebp source code - it only has build scripts (install_webp.sh) that specify libwebp-1.2.1 as an external dependency to download and link. The vulnerable code lives in the separate libwebp repository, not in Pillow's codebase. Per the DOC-ONLY PATCH ru...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2023-50447",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:f823a8d1-e9dc-5668-a39a-932e31538cb6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50447 is fixed in version 8.4.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2024-28219",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:07b162a3-94a8-52f9-a27b-b48d25af0325",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28219 is fixed in version 8.4.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-42308",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:a9fab433-febd-58b0-a8d3-57b032c83c78",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 8.4.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-42310",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:c6e91cfa-4c93-5180-84e4-23ee284352c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42310 is fixed in version 8.4.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-54059",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b123fecf-f288-5577-8e59-e0afc6a65c55",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 8.4.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-54060",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:af5e9d3d-f788-50a7-a5f4-301c05ed76c7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54060 is fixed in version 8.4.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-55379",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b8af8701-5e12-5606-b5d1-12348a7a5773",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 8.4.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-55380",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:c62c3734-1981-5b75-987a-026fc4a52789",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 8.4.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-55798",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:df152554-b512-5d22-8d6b-5eda2d884188",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55798 is fixed in version 8.4.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59197",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:969e093b-8def-5f35-8742-f81098bc8372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 8.4.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59198",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:425ddf28-3917-5e81-8c84-3d19ea4934de",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 8.4.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59199",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:865096c2-b3b0-5ea8-8d43-acd1efab5569",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 8.4.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59200",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:7938e9c4-a0f8-504f-b772-bf2551c686a9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 8.4.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59204",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:95e8a759-1809-5397-a971-34043f78b2cf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 8.4.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59205",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:bc806118-fb54-57f8-b554-63938d241203",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 8.4.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "GHSA-4fx9-vc88-q2xc",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:072b13f0-252b-51d5-a3cb-04c67b7b83de",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4fx9-vc88-q2xc is fixed in version 8.4.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "GHSA-56pw-mpj4-fxww",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:1ad79a7c-da26-5ddd-b445-5b42baa781fb",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-56pw-mpj4-fxww is a false positive for pillow 8.4.0.post7+tuxcare."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
    }
  ]
}