{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4462d427-2e9c-5e94-ba20-a8a61275fd15",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "pip",
      "purl": "pkg:pypi/pip@9.0.0.post2+tuxcare",
      "type": "library",
      "bom-ref": "pkg:pypi/pip@9.0.0.post2+tuxcare",
      "version": "9.0.0.post2+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2019-20916",
      "affects": [
        {
          "ref": "pkg:pypi/pip@9.0.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:ee47156b-d9a6-504b-a5a2-1893d56a4d77",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-20916 is fixed in version 9.0.0.post2+tuxcare of pip."
      }
    },
    {
      "id": "CVE-2021-3572",
      "affects": [
        {
          "ref": "pkg:pypi/pip@9.0.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:8bc86f99-8105-5ff9-b112-db948f3eb2ba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-3572 is fixed in version 9.0.0.post2+tuxcare of pip."
      }
    },
    {
      "id": "CVE-2023-5752",
      "affects": [
        {
          "ref": "pkg:pypi/pip@9.0.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:2b6afa89-7264-5230-a287-48fb550cd3e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-5752 is fixed in version 9.0.0.post2+tuxcare of pip."
      }
    },
    {
      "id": "CVE-2025-8869",
      "affects": [
        {
          "ref": "pkg:pypi/pip@9.0.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:48d7a737-12bc-5664-9db6-3a14d34611c7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-8869 is fixed in version 9.0.0.post2+tuxcare of pip."
      }
    },
    {
      "id": "CVE-2026-13346",
      "affects": [
        {
          "ref": "pkg:pypi/pip@9.0.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b1ac64e0-7d71-548d-a15b-6f9aa5771d34",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-13346 affects version 9.0.0.post2+tuxcare of pip, and is fixed in 9.0.0.post3+tuxcare."
      }
    },
    {
      "id": "CVE-2026-1703",
      "affects": [
        {
          "ref": "pkg:pypi/pip@9.0.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:8e73bd6c-94c5-5a74-865b-8c29559d7929",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1703 affects version 9.0.0.post2+tuxcare of pip."
      }
    },
    {
      "id": "CVE-2026-3219",
      "affects": [
        {
          "ref": "pkg:pypi/pip@9.0.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:ac0877ce-e03e-5cf0-b97f-34642a6cc32c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-3219 affects version 9.0.0.post2+tuxcare of pip, and is fixed in 9.0.0.post3+tuxcare."
      }
    },
    {
      "id": "CVE-2026-6357",
      "affects": [
        {
          "ref": "pkg:pypi/pip@9.0.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:697c7925-9db4-569f-aeb0-04f6117bcfeb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6357 affects version 9.0.0.post2+tuxcare of pip, and is fixed in 9.0.0.post3+tuxcare."
      }
    },
    {
      "id": "CVE-2026-8643",
      "affects": [
        {
          "ref": "pkg:pypi/pip@9.0.0.post2+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4d2d8e9e-f223-5ce0-8cb5-427922c83405",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-8643 is fixed in version 9.0.0.post2+tuxcare of pip."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pip@9.0.0.post2+tuxcare"
    }
  ]
}