{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2157b8f4-3c63-5abd-bd65-4e60985ae87a",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "django",
      "purl": "pkg:pypi/django@5.0.2.post9+tuxcare",
      "type": "library",
      "bom-ref": "pkg:pypi/django@5.0.2.post9+tuxcare",
      "version": "5.0.2.post9+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2024-27351",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:671ac2b6-4a18-5ac4-b1d6-91d501c86741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27351 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-38875",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:56eba88c-404c-5904-87f6-f8d75464bca5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38875 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-39329",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:2a02fd18-6837-55e7-b586-6c1f6e840a6a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39329 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-39330",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:ccfa5a3f-cb0f-56d5-896c-718dd629f0a4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39330 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-39614",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:c14c2f02-bf1a-5ad0-8c10-e7f947b43a59",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39614 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-41989",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e2e64b8b-99ee-5c5d-8312-26a42d8bc9ef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-41989 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-41990",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:f5f0b4a9-88dc-5328-ba45-259c7b4f4d93",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-41990 does not affect version 5.0.2.post9+tuxcare of django. not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-41991",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:a208f366-243c-59a5-af18-828bd3250d35",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-41991 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-42005",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e4788b98-745f-513c-bde9-c23bd9442702",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-42005 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-45230",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:125dafcc-3002-5fbd-9f9e-90f9163487f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45230 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-45231",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:87be468f-47e7-5172-8c40-e800084c9a70",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45231 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-53907",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:ed43ebf7-05fb-5d29-9d37-507483fb922c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-53907 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-53908",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:78a369f4-cef1-5dab-a072-4e2168eac7d5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-53908 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-56374",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:52102e06-fc3f-508a-af2b-c5e88f0d9a60",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56374 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-13372",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:a0bf0986-cf3e-5e5b-a0e6-42d03ba46e46",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13372 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-13473",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:350186e8-f2e0-5c7b-98c6-4e9e60de85df",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13473 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-14550",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4e4d4bdf-332c-5920-872a-677b23cae504",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14550 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-26699",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:59342025-e7b2-5e25-be25-78e6457787d1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-26699 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-27556",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:7afb27b6-be1f-58cc-a0f2-6963286b65da",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27556 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-48432",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:78d8b0a2-6826-544d-9f2e-ab2a5542895f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48432 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-57833",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:604f931f-635c-5fe1-b216-a71c38620e1d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-64458",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b5d1364a-2580-558e-814f-6746e38f83c1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64458 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-64459",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:67a4197c-f9d6-5328-a06c-9a2acaa6785c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64459 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-64460",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:17d2bae3-d0c5-5e26-9f5e-9510b5695fa3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64460 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-1207",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:494fe7a0-435a-50ab-b217-89e8b36c510b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1207 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-1285",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:de945767-d58f-518c-8ceb-7a3ff1d005f9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-1287",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4d33fad7-8a4c-52a4-8c31-7cb3f5b30200",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1287 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-1312",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:478e003b-3ed4-5124-8446-43e13f4b5c9a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1312 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-48587",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e7716fbe-c477-5cd3-99fd-6cbc29cef29b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48587 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-48588",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:2099eae5-6c7d-5408-bb47-aa5f1183c4d9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48588 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-53877",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:16cb42fa-efaf-524a-b0ee-eb9fb4b9bed0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53877 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-53878",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:38e857a0-d757-51e7-b1a6-307ab0500793",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-53878 does not affect version 5.0.2.post9+tuxcare of django. not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-6873",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:43b63210-73d2-51ec-a160-31349586ccbd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6873 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-8404",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:a15e1b19-cc04-524e-bbde-b8e7f6dde4ac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-8404 is fixed in version 5.0.2.post9+tuxcare of django."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/django@5.0.2.post9+tuxcare"
    }
  ]
}