{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fae3e6c2-61a2-5f1f-81b9-c0f0c943ea87",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "django",
      "purl": "pkg:pypi/django@4.0.post19+tuxcare",
      "type": "library",
      "bom-ref": "pkg:pypi/django@4.0.post19+tuxcare",
      "version": "4.0.post19+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-45115",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:891a4e49-ee06-5545-9972-cc582b0772f6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2021-45116",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:39fe11bf-ffea-5201-b1ff-308ca9881f9d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2021-45452",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:8856186f-1408-557e-ac45-a8c9a8145089",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2022-22818",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:feee51fd-4a80-577d-955f-afb6963e9a68",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2022-23833",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:a303a27c-0c85-567b-8ec6-0c9f9cd2b323",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23833 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2022-28346",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:7f7622a0-941e-5c34-b2fd-ecd464bac028",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2022-28347",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:20787583-5c75-5e78-a4c3-4812bb1aad39",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2022-34265",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:22134239-3351-5291-a146-a0029aa336ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2022-36359",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:1facd468-f707-5c71-8757-14b4c4da0852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2022-41323",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:d5fe7525-152a-51d4-8d98-34a84e71ab1b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2023-23969",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:990d4f4b-e4da-5b14-9659-88dc61a7457b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2023-24580",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:3c05e111-1882-57a0-ad2e-d7680193e217",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2023-31047",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:fd3a2eee-1765-591a-9816-5d7c838f3554",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-31047 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2023-36053",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:06f2fcd9-c5b4-5837-9f4f-4a54180f5a92",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-36053 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2023-43665",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:eb675bcf-29bf-5397-a61d-33295fbe2f65",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-43665 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2023-46695",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:7326fad0-2935-5925-a079-a5f967136636",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46695 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-45231",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:5e4a2837-db52-5476-a029-d174ee46190d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45231 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-13372",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:1cd2660d-c94f-5448-83c4-a4c894654d4a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13372 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-13473",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:0e46ebad-34ec-5b8e-9680-6705f713f63e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13473 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-14550",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:5025c698-87ef-5576-af4b-3b59f6f0a822",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14550 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-48432",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:8a4e4956-e323-5cec-b67d-e5561edd1645",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48432 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-57833",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4b3f1f5f-c16f-533f-ac72-e93495863c48",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-64458",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:d52a17dd-c074-5f9e-a888-7d9a213d6aa4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64458 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-64459",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:92641d4a-7b72-5025-b767-434ff9f00b20",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64459 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-64460",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:7f94a12c-4b04-5035-ac10-7b30b7a96174",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64460 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-1207",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:420bc634-2779-5a11-a97d-23019a36df3b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1207 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-1285",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:0debdb63-5748-5c73-b718-c622b82fe6e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1285 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-1287",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:0782a863-516d-5f7a-a30c-7ea169e2b2ef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1287 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-1312",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:06fc3baa-6c4a-5497-9ef1-07374f3b0ca8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1312 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-48587",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:3912233b-7be8-59e4-ab64-aaa84257d3c9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48587 affects version 4.0.post19+tuxcare of django, and is fixed in 4.0.post20+tuxcare."
      }
    },
    {
      "id": "CVE-2026-48588",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:c22ed789-0296-5baa-8d1a-b89fa81c35c9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48588 is fixed in version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-53877",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:6eccaf99-a8fa-5d3e-b9ab-be6987e87ade",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53877 affects version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-53878",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:0c27c911-4426-5935-ab32-29c600ba4eb4",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-53878 does not affect version 4.0.post19+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe...",
        "justification": "protected_at_runtime"
      }
    },
    {
      "id": "CVE-2026-6873",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e033ce32-162b-514a-8a58-b3c5789b2569",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6873 affects version 4.0.post19+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-8404",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post19+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:d7aac988-6791-5758-80f4-01bf7d2f1840",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-8404 is fixed in version 4.0.post19+tuxcare of django."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/django@4.0.post19+tuxcare"
    }
  ]
}