{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:dc6b23f7-2479-538e-b0d4-66e1442626a7",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "pillow",
      "purl": "pkg:pypi/pillow@8.4.0.post2+tuxcare",
      "type": "library",
      "bom-ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare",
      "version": "8.4.0.post2+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2022-22815",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b8ca8410-127d-5351-b547-40d44f1a8e9d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22815 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare."
      }
    },
    {
      "id": "CVE-2022-22816",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:2d6e385d-eb77-5140-a963-f24b847ce66b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22816 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare."
      }
    },
    {
      "id": "CVE-2022-22817",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4338ae3d-37d0-5c97-97bf-4ee1789f061a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22817 is fixed in version 8.4.0.post2+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2022-45198",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:f42a96c5-3920-527b-911c-eeaab5bf3585",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45198 is fixed in version 8.4.0.post2+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2023-4863",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:2c13da22-9c10-5888-9e96-b0d58bfaf5c4",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-4863 does not affect version 8.4.0.post2+tuxcare of pillow. not_affected \u2014 CVE-2023-4863 is a heap buffer overflow vulnerability in libwebp's huffman_utils.c (BuildHuffmanTable function). Pillow 8.4.0 does not contain libwebp source code - it only has build scripts (install_webp.sh) that specify libwebp-1.2.1 as an external dependency to download and link. The vulnerable code lives in the separate libwebp repository, not in Pillow's codebase. Per the DOC-ONLY PATCH ru...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2023-50447",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:af4c54c9-6077-510b-8fa9-2727435c73c8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50447 is fixed in version 8.4.0.post2+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2024-28219",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:f191696b-53a4-5f37-aee9-0bb6d32af5e4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-28219 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare."
      }
    },
    {
      "id": "CVE-2026-42308",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b74610c9-24b4-5540-b86c-67c6195fbee5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 8.4.0.post2+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-42310",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:431d098a-7b09-51ad-ae92-f7b7de2fdcce",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 8.4.0.post2+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-54059",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:aae0a5ea-6ee1-5ba1-99c9-3cee75599b8e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 8.4.0.post2+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-54060",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:d6000c96-27de-546b-bd40-72abac57c209",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54060 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post3+tuxcare."
      }
    },
    {
      "id": "CVE-2026-55379",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:f06c7941-8fe9-5a5a-9bde-06eb15f30378",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 8.4.0.post2+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-55380",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:88a18bab-8208-5f07-ae04-c88b500ef8a2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 8.4.0.post2+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-55798",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:c04c18c3-367d-5abd-b948-104fa094e263",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55798 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post4+tuxcare."
      }
    },
    {
      "id": "CVE-2026-59197",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:f8ca872d-79b5-5ddc-91d5-de64faad78fa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 8.4.0.post2+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59198",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:32faf680-d5ec-5dac-b1fe-ec063d80ef1a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 8.4.0.post2+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59199",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:c25d7678-56e9-5a4c-a224-d4f4ba10e3d1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 8.4.0.post2+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59200",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:77ef0f93-fb7d-5cc7-b5c9-c181810aebdb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 8.4.0.post2+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59204",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:3734bbc5-0288-5865-9bce-bf926f2ffb7e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 8.4.0.post2+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59205",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:49e98eba-1e3c-5901-a1b4-d8a6a8cea38d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 8.4.0.post2+tuxcare of pillow."
      }
    },
    {
      "id": "GHSA-4fx9-vc88-q2xc",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:d937e34c-899c-5839-abd5-cc541f4aa8c0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4fx9-vc88-q2xc affects version 8.4.0.post2+tuxcare of pillow."
      }
    },
    {
      "id": "GHSA-56pw-mpj4-fxww",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:eb2219f8-ecce-5c3a-afe1-8d46d05794bf",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-56pw-mpj4-fxww is a false positive for pillow 8.4.0.post2+tuxcare."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
    }
  ]
}