{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:43a8402b-473d-5ad6-9d1e-ef93f564e29a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.boot/spring-boot-antlib@2.7.18-tuxcare.12",
      "type": "library",
      "group": "org.springframework.boot",
      "name": "spring-boot-antlib",
      "version": "2.7.18-tuxcare.12",
      "purl": "pkg:maven/org.springframework.boot/spring-boot-antlib@2.7.18-tuxcare.12"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b366c000-070f-5e60-a6a8-3b470a7b4488",
      "id": "CVE-2023-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-38286 is fixed in version 2.7.18-tuxcare.12 of org.springframework.boot:spring-boot-antlib."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-antlib@2.7.18-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84b61351-ca2e-5d33-8336-0cf26f0458b7",
      "id": "CVE-2024-38807",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38807 is fixed in version 2.7.18-tuxcare.12 of org.springframework.boot:spring-boot-antlib."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-antlib@2.7.18-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef455fc4-7242-5f89-b023-33182da1137a",
      "id": "CVE-2025-22235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22235 is fixed in version 2.7.18-tuxcare.12 of org.springframework.boot:spring-boot-antlib."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-antlib@2.7.18-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d023e99a-f8b7-58ba-b871-6d0286cfad25",
      "id": "CVE-2026-22733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22733 affects version 2.7.18-tuxcare.12 of org.springframework.boot:spring-boot-antlib."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-antlib@2.7.18-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:367c6e8f-4d5b-5bd0-a084-b96376c39cf5",
      "id": "CVE-2026-40972",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40972 affects version 2.7.18-tuxcare.12 of org.springframework.boot:spring-boot-antlib."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-antlib@2.7.18-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:213ff585-8964-5c42-8e8b-795a98221990",
      "id": "CVE-2026-40973",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40973 affects version 2.7.18-tuxcare.12 of org.springframework.boot:spring-boot-antlib."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-antlib@2.7.18-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f601461-67fe-5b89-beb2-11aaaea27a35",
      "id": "CVE-2026-40974",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40974 affects version 2.7.18-tuxcare.12 of org.springframework.boot:spring-boot-antlib."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-antlib@2.7.18-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fa9579b-4b06-5982-8d62-bbc5b60bbd37",
      "id": "CVE-2026-40975",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40975 affects version 2.7.18-tuxcare.12 of org.springframework.boot:spring-boot-antlib."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-antlib@2.7.18-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1bec26f-c0a9-5bd0-bb1e-07d7df9f01ae",
      "id": "CVE-2026-40977",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40977 affects version 2.7.18-tuxcare.12 of org.springframework.boot:spring-boot-antlib."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-antlib@2.7.18-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34de6b08-25a7-59d1-ae8b-cf3683f1b4a1",
      "id": "CVE-2026-40992",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-40992 does not affect version 2.7.18-tuxcare.12 of org.springframework.boot:spring-boot-antlib. not_affected \u2014 Spring Boot 2.7.18 is NOT AFFECTED by CVE-2026-40992. The vulnerability exists in the SSL auto-configuration feature (spring.mail.ssl.*) introduced in Spring Boot 3.4+/3.5+/4.0+, which does not exist in version 2.7.18. The target version uses a simpler architecture where all SSL configuration is manual via spring.mail.properties.*, and the auto-configuration does not handle SSL at all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-antlib@2.7.18-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48234db6-32e4-504c-afa7-f880d03c7e8a",
      "id": "CVE-2026-41001",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41001 affects version 2.7.18-tuxcare.12 of org.springframework.boot:spring-boot-antlib."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-antlib@2.7.18-tuxcare.12"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.boot/spring-boot-antlib@2.7.18-tuxcare.12"
    }
  ]
}