{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:701f66b6-53fa-53ed-9fc9-7f50479f34ce",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-client@2.7.16-tuxcare.2",
      "type": "library",
      "group": "org.springframework.boot",
      "name": "spring-boot-starter-oauth2-client",
      "version": "2.7.16-tuxcare.2",
      "purl": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-client@2.7.16-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9e4cde09-27b2-5bec-ba35-911b8fc4a456",
      "id": "CVE-2023-34055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34055 is fixed in version 2.7.16-tuxcare.2 of org.springframework.boot:spring-boot-starter-oauth2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-client@2.7.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8beedc4a-1cef-53c3-9007-3793fa242e57",
      "id": "CVE-2023-38286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-38286 affects version 2.7.16-tuxcare.2 of org.springframework.boot:spring-boot-starter-oauth2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-client@2.7.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e59c68ab-024c-5949-a778-0d9dc8e7444e",
      "id": "CVE-2024-38807",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38807 affects version 2.7.16-tuxcare.2 of org.springframework.boot:spring-boot-starter-oauth2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-client@2.7.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a5ce92f-bac1-5ccf-b612-75f0d2ca2801",
      "id": "CVE-2025-22235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22235 is fixed in version 2.7.16-tuxcare.2 of org.springframework.boot:spring-boot-starter-oauth2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-client@2.7.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:113dc950-5ca5-553e-b97e-8247e3fabba6",
      "id": "CVE-2026-22733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22733 is fixed in version 2.7.16-tuxcare.2 of org.springframework.boot:spring-boot-starter-oauth2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-client@2.7.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1290a5e2-599c-5f44-af2a-ebcad9eb9e9b",
      "id": "CVE-2026-40972",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40972 is fixed in version 2.7.16-tuxcare.2 of org.springframework.boot:spring-boot-starter-oauth2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-client@2.7.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc68d679-eb6b-55cf-85f1-1fa30e38ae87",
      "id": "CVE-2026-40973",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40973 affects version 2.7.16-tuxcare.2 of org.springframework.boot:spring-boot-starter-oauth2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-client@2.7.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf3879b1-98e7-505e-a1f5-63c7e18c684d",
      "id": "CVE-2026-40974",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40974 affects version 2.7.16-tuxcare.2 of org.springframework.boot:spring-boot-starter-oauth2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-client@2.7.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46107437-f6c3-5d5f-a9d5-3ebe5fba93c4",
      "id": "CVE-2026-40975",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40975 affects version 2.7.16-tuxcare.2 of org.springframework.boot:spring-boot-starter-oauth2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-client@2.7.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9694ec7b-6f4e-5085-9aa2-90aaf68505cd",
      "id": "CVE-2026-40977",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40977 affects version 2.7.16-tuxcare.2 of org.springframework.boot:spring-boot-starter-oauth2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-client@2.7.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6664862a-f0ac-5fc7-8666-aa98c98a533e",
      "id": "CVE-2026-40992",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40992 affects version 2.7.16-tuxcare.2 of org.springframework.boot:spring-boot-starter-oauth2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-client@2.7.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eda0af6a-93ce-583c-b031-4d34c26b9769",
      "id": "CVE-2026-41001",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41001 affects version 2.7.16-tuxcare.2 of org.springframework.boot:spring-boot-starter-oauth2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-client@2.7.16-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-client@2.7.16-tuxcare.2"
    }
  ]
}