{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0ce36e22-b3f8-53dc-9953-a9710b99684d",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "starlette",
      "purl": "pkg:pypi/starlette@0.25.0.post1+tuxcare",
      "type": "library",
      "bom-ref": "pkg:pypi/starlette@0.25.0.post1+tuxcare",
      "version": "0.25.0.post1+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2023-29159",
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.25.0.post1+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:214dfa92-71ed-50b5-867f-2f05cd5fb5b7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-29159 is fixed in version 0.25.0.post1+tuxcare of starlette."
      }
    },
    {
      "id": "CVE-2024-47874",
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.25.0.post1+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:5ae76f94-9f4b-5d89-a0a3-5410d6ffa871",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47874 is fixed in version 0.25.0.post1+tuxcare of starlette."
      }
    },
    {
      "id": "CVE-2025-54121",
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.25.0.post1+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e91c0386-2efc-5483-9e49-36edabbfa31c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54121 is fixed in version 0.25.0.post1+tuxcare of starlette."
      }
    },
    {
      "id": "CVE-2025-62727",
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.25.0.post1+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:f7531d70-6a6e-5b72-b970-3c5be94db267",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-62727 does not affect version 0.25.0.post1+tuxcare of starlette. CVE-2025-62727 is a Range header parsing flaw in FileResponse. That parsing was introduced upstream in starlette 0.39.0; version 0.25.0 predates it. Verified on tuxcare-current/0.25.0: the string \"Range\" does not occur anywhere in the starlette package, and FileResponse implements no range handling. Same disposition and same reasoning as starlette 0.27.0 (VPV 81209), which is already not_affected with justification code_not_present.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-48710",
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.25.0.post1+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:0fcbcd3b-4d80-57e9-afc9-6cf0bb7877ae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48710 is fixed in version 0.25.0.post1+tuxcare of starlette."
      }
    },
    {
      "id": "CVE-2026-48817",
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.25.0.post1+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:16209767-b46a-530c-b86e-24edb9815909",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48817 is fixed in version 0.25.0.post1+tuxcare of starlette."
      }
    },
    {
      "id": "CVE-2026-48818",
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.25.0.post1+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:67e12da1-c752-5577-afcb-10814e661063",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48818 is fixed in version 0.25.0.post1+tuxcare of starlette."
      }
    },
    {
      "id": "CVE-2026-54282",
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.25.0.post1+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:c89a6f67-77db-5715-8d64-e18330c88e53",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54282 is fixed in version 0.25.0.post1+tuxcare of starlette."
      }
    },
    {
      "id": "CVE-2026-54283",
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.25.0.post1+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:34c33c9a-108e-5a53-bf59-e267cb79aa87",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54283 is fixed in version 0.25.0.post1+tuxcare of starlette."
      }
    },
    {
      "id": "GHSA-93gm-qmq6-w238",
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.25.0.post1+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:59826f2d-e6d7-5843-89f6-75043bb3ddc5",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-93gm-qmq6-w238 is a false positive for starlette 0.25.0.post1+tuxcare."
      }
    },
    {
      "id": "GHSA-qj8w-rv5x-2v9h",
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.25.0.post1+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:0fd3e815-9cee-59cd-bf66-d692db19688a",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-qj8w-rv5x-2v9h is a false positive for starlette 0.25.0.post1+tuxcare."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/starlette@0.25.0.post1+tuxcare"
    }
  ]
}