{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1f8dcb1b-797f-553e-bb80-218d072abdc3",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.boot/spring-boot-starter@2.4.6-tuxcare.4",
      "type": "library",
      "group": "org.springframework.boot",
      "name": "spring-boot-starter",
      "version": "2.4.6-tuxcare.4",
      "purl": "pkg:maven/org.springframework.boot/spring-boot-starter@2.4.6-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2a74ee44-17c0-58b1-86eb-eb15b491d0c5",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dabb8fba-e9e8-512d-9c5f-610b392ca2a0",
      "id": "CVE-2023-20873",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20873 is fixed in version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6114534a-7620-581b-aad8-912e8eaf4530",
      "id": "CVE-2023-20883",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20883 is fixed in version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b92b56e-2be2-50b1-8135-30805dddc4f2",
      "id": "CVE-2023-34055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34055 is fixed in version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:951ade35-8ea6-5762-b91a-2a6625b53fcc",
      "id": "CVE-2023-38286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-38286 affects version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37ee2b80-922a-5972-b8af-a3b2e2167a8b",
      "id": "CVE-2024-38807",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38807 affects version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cf5be1a-b274-5e92-b79c-595b9c85a393",
      "id": "CVE-2025-22235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22235 is fixed in version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8228a93f-2e89-5e4d-b9e0-9b30d531d395",
      "id": "CVE-2026-22733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22733 is fixed in version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b892a744-7b8b-52bb-92d9-5bdca06f3e40",
      "id": "CVE-2026-40972",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40972 is fixed in version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c34824cf-08bf-563c-a7b1-dc46a7df4e5a",
      "id": "CVE-2026-40973",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40973 affects version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aaf403bd-3b9e-5350-bff1-2663cc26dd31",
      "id": "CVE-2026-40974",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40974 affects version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0008724f-65cc-5643-80b7-3f2793d58c0d",
      "id": "CVE-2026-40975",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40975 is fixed in version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea464692-e75c-579f-996b-1c7e23512799",
      "id": "CVE-2026-40977",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40977 is fixed in version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9cde9ce-6c8e-5cf6-9001-48e078277792",
      "id": "CVE-2026-40992",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40992 affects version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5a828af-4f6c-5a9d-9b5f-44530928809e",
      "id": "CVE-2026-41001",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41001 affects version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter@2.4.6-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.boot/spring-boot-starter@2.4.6-tuxcare.4"
    }
  ]
}