{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:da726533-c05a-51a3-83a9-0c0b12c119ed",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.boot/spring-boot-jarmode-layertools@2.7.16-tuxcare.4",
      "type": "library",
      "group": "org.springframework.boot",
      "name": "spring-boot-jarmode-layertools",
      "version": "2.7.16-tuxcare.4",
      "purl": "pkg:maven/org.springframework.boot/spring-boot-jarmode-layertools@2.7.16-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f5ed7f75-b088-5f7b-828c-7c010409d6f3",
      "id": "CVE-2023-34055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34055 is fixed in version 2.7.16-tuxcare.4 of org.springframework.boot:spring-boot-jarmode-layertools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-jarmode-layertools@2.7.16-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:862b96da-9036-570b-9276-9b3738074876",
      "id": "CVE-2023-38286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-38286 affects version 2.7.16-tuxcare.4 of org.springframework.boot:spring-boot-jarmode-layertools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-jarmode-layertools@2.7.16-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:747834c7-12c1-5237-9a9a-296f6e546b1f",
      "id": "CVE-2024-38807",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38807 affects version 2.7.16-tuxcare.4 of org.springframework.boot:spring-boot-jarmode-layertools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-jarmode-layertools@2.7.16-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84a7f7e2-716f-585f-acce-32f378389a2f",
      "id": "CVE-2025-22235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22235 is fixed in version 2.7.16-tuxcare.4 of org.springframework.boot:spring-boot-jarmode-layertools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-jarmode-layertools@2.7.16-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5df30279-cca5-5b95-a289-48083e0fcc4c",
      "id": "CVE-2026-22733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22733 is fixed in version 2.7.16-tuxcare.4 of org.springframework.boot:spring-boot-jarmode-layertools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-jarmode-layertools@2.7.16-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e9df294-d410-5705-969d-80221b24173e",
      "id": "CVE-2026-40972",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40972 is fixed in version 2.7.16-tuxcare.4 of org.springframework.boot:spring-boot-jarmode-layertools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-jarmode-layertools@2.7.16-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5f01d5a-8318-537e-bd4c-467d61410697",
      "id": "CVE-2026-40973",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40973 is fixed in version 2.7.16-tuxcare.4 of org.springframework.boot:spring-boot-jarmode-layertools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-jarmode-layertools@2.7.16-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:157687f8-4564-5795-a6e9-fb2603c174f2",
      "id": "CVE-2026-40974",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40974 affects version 2.7.16-tuxcare.4 of org.springframework.boot:spring-boot-jarmode-layertools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-jarmode-layertools@2.7.16-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fe7ae63-26e6-56ce-aff3-3e2a7229d922",
      "id": "CVE-2026-40975",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40975 is fixed in version 2.7.16-tuxcare.4 of org.springframework.boot:spring-boot-jarmode-layertools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-jarmode-layertools@2.7.16-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec22d932-a2b3-50a5-b7c3-2b2b13ddfdfa",
      "id": "CVE-2026-40977",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40977 is fixed in version 2.7.16-tuxcare.4 of org.springframework.boot:spring-boot-jarmode-layertools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-jarmode-layertools@2.7.16-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9348d2b-7967-5ce3-8349-c6034c8b81f2",
      "id": "CVE-2026-40992",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40992 affects version 2.7.16-tuxcare.4 of org.springframework.boot:spring-boot-jarmode-layertools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-jarmode-layertools@2.7.16-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83dc2f34-3433-5521-90b7-f20e122f2270",
      "id": "CVE-2026-41001",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41001 affects version 2.7.16-tuxcare.4 of org.springframework.boot:spring-boot-jarmode-layertools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-jarmode-layertools@2.7.16-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.boot/spring-boot-jarmode-layertools@2.7.16-tuxcare.4"
    }
  ]
}