{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:386da0cd-b5b9-51fc-ab9e-3400daf6b379",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.boot/spring-boot-actuator@2.4.6-tuxcare.3",
      "type": "library",
      "group": "org.springframework.boot",
      "name": "spring-boot-actuator",
      "version": "2.4.6-tuxcare.3",
      "purl": "pkg:maven/org.springframework.boot/spring-boot-actuator@2.4.6-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:08114254-217f-5423-a885-b6babf9d4643",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 2.4.6-tuxcare.3 of org.springframework.boot:spring-boot-actuator."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-actuator@2.4.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f9fd331-5e91-5ac0-b364-8a2c2971a383",
      "id": "CVE-2023-20873",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20873 is fixed in version 2.4.6-tuxcare.3 of org.springframework.boot:spring-boot-actuator."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-actuator@2.4.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4db73276-e7b4-5be9-8e65-8249d8a1aa77",
      "id": "CVE-2023-20883",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20883 is fixed in version 2.4.6-tuxcare.3 of org.springframework.boot:spring-boot-actuator."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-actuator@2.4.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04d25fe9-56b8-5f17-b292-026ab74501ca",
      "id": "CVE-2023-34055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34055 is fixed in version 2.4.6-tuxcare.3 of org.springframework.boot:spring-boot-actuator."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-actuator@2.4.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:177904aa-be86-560a-901f-eb4dca7d5938",
      "id": "CVE-2023-38286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-38286 affects version 2.4.6-tuxcare.3 of org.springframework.boot:spring-boot-actuator."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-actuator@2.4.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a6a575d-83b0-5046-a916-94abd25c37e3",
      "id": "CVE-2024-38807",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38807 affects version 2.4.6-tuxcare.3 of org.springframework.boot:spring-boot-actuator."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-actuator@2.4.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b08a8f7f-d597-5d37-a595-3f63ce8eaf12",
      "id": "CVE-2025-22235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22235 is fixed in version 2.4.6-tuxcare.3 of org.springframework.boot:spring-boot-actuator."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-actuator@2.4.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b76a089e-7f5f-57b3-bfa3-627c319b98b9",
      "id": "CVE-2026-22733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22733 affects version 2.4.6-tuxcare.3 of org.springframework.boot:spring-boot-actuator."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-actuator@2.4.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2d0c90d-194b-560b-9658-8bc875018a9d",
      "id": "CVE-2026-40972",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40972 affects version 2.4.6-tuxcare.3 of org.springframework.boot:spring-boot-actuator."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-actuator@2.4.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:941e5109-f861-5434-9e24-16f66cb87865",
      "id": "CVE-2026-40973",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40973 affects version 2.4.6-tuxcare.3 of org.springframework.boot:spring-boot-actuator."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-actuator@2.4.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:899f3f55-e53b-567d-980a-317affad2d02",
      "id": "CVE-2026-40974",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40974 affects version 2.4.6-tuxcare.3 of org.springframework.boot:spring-boot-actuator."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-actuator@2.4.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2c6c84e-5b32-5347-a421-5af16c263994",
      "id": "CVE-2026-40975",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40975 affects version 2.4.6-tuxcare.3 of org.springframework.boot:spring-boot-actuator."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-actuator@2.4.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c2e7173-8ada-5614-a384-378ec9a779d7",
      "id": "CVE-2026-40977",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40977 affects version 2.4.6-tuxcare.3 of org.springframework.boot:spring-boot-actuator."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-actuator@2.4.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:224980d6-b7e2-59fc-9729-ef36251eb223",
      "id": "CVE-2026-40992",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40992 affects version 2.4.6-tuxcare.3 of org.springframework.boot:spring-boot-actuator."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-actuator@2.4.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bfbed76-9f14-5d0c-9bae-1f692f213513",
      "id": "CVE-2026-41001",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41001 affects version 2.4.6-tuxcare.3 of org.springframework.boot:spring-boot-actuator."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-actuator@2.4.6-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.boot/spring-boot-actuator@2.4.6-tuxcare.3"
    }
  ]
}