{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8658e1e2-d766-594b-b6d3-c0a00af1214d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.boot/spring-boot-test@2.4.5-tuxcare.1",
      "type": "library",
      "group": "org.springframework.boot",
      "name": "spring-boot-test",
      "version": "2.4.5-tuxcare.1",
      "purl": "pkg:maven/org.springframework.boot/spring-boot-test@2.4.5-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:8f0078c6-e365-52d9-a03a-fe62dde5bc97",
      "id": "CVE-2023-20873",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20873 is fixed in version 2.4.5-tuxcare.1 of org.springframework.boot:spring-boot-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-test@2.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1deb7e0e-262e-59ba-834a-3359c86a05be",
      "id": "CVE-2023-20883",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20883 is fixed in version 2.4.5-tuxcare.1 of org.springframework.boot:spring-boot-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-test@2.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be21fb91-88c5-5f26-b1bb-c5b0003adda1",
      "id": "CVE-2023-34055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34055 is fixed in version 2.4.5-tuxcare.1 of org.springframework.boot:spring-boot-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-test@2.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d7a5913-5c32-536b-9573-5c8824ba9553",
      "id": "CVE-2023-38286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-38286 affects version 2.4.5-tuxcare.1 of org.springframework.boot:spring-boot-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-test@2.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5a8b2ef-2372-5f01-9ab9-c7d25970d3ab",
      "id": "CVE-2024-38807",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38807 affects version 2.4.5-tuxcare.1 of org.springframework.boot:spring-boot-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-test@2.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d9df815-75ee-5b6e-9fd5-5d7674256969",
      "id": "CVE-2025-22235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22235 is fixed in version 2.4.5-tuxcare.1 of org.springframework.boot:spring-boot-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-test@2.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1f6d410-0276-50da-aa9c-7993b0a8ee59",
      "id": "CVE-2026-22733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22733 affects version 2.4.5-tuxcare.1 of org.springframework.boot:spring-boot-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-test@2.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af2160b4-cf74-5aab-a1a1-3dea74c29208",
      "id": "CVE-2026-40972",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40972 affects version 2.4.5-tuxcare.1 of org.springframework.boot:spring-boot-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-test@2.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af989ef7-8203-5dff-acb7-465591fcb0a0",
      "id": "CVE-2026-40973",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40973 affects version 2.4.5-tuxcare.1 of org.springframework.boot:spring-boot-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-test@2.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:996edcdd-0715-51bf-aa5f-1f25f5a2e1b9",
      "id": "CVE-2026-40974",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40974 affects version 2.4.5-tuxcare.1 of org.springframework.boot:spring-boot-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-test@2.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f59dc1c6-5671-5845-89ea-843cded6df64",
      "id": "CVE-2026-40975",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40975 affects version 2.4.5-tuxcare.1 of org.springframework.boot:spring-boot-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-test@2.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:523cd88c-1052-55a7-8fae-6a62726414f8",
      "id": "CVE-2026-40977",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40977 affects version 2.4.5-tuxcare.1 of org.springframework.boot:spring-boot-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-test@2.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68a27519-67e2-59b0-be08-3971b6748ae3",
      "id": "CVE-2026-40992",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-40992 does not affect version 2.4.5-tuxcare.1 of org.springframework.boot:spring-boot-test. not_affected \u2014 Spring Boot 2.7.18 is not affected by CVE-2026-40992. The vulnerability exists in the SSL auto-configuration feature introduced in Spring Boot 3.x/4.x (controlled via spring.mail.ssl.enabled and spring.mail.ssl.bundle properties). This SSL auto-configuration feature does not exist in version 2.7.18. In 2.7.18, users must manually configure all JavaMail properties via spring.mail.properties.*, i..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-test@2.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a06f98b-8852-54c2-b2cc-49855be2e7ba",
      "id": "CVE-2026-41001",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41001 affects version 2.4.5-tuxcare.1 of org.springframework.boot:spring-boot-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-test@2.4.5-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.boot/spring-boot-test@2.4.5-tuxcare.1"
    }
  ]
}