{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:79b8520b-696d-5263-bff6-182f180c5475",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.boot/org.springframework.boot.gradle.plugin@2.4.6-tuxcare.9",
      "type": "library",
      "group": "org.springframework.boot",
      "name": "org.springframework.boot.gradle.plugin",
      "version": "2.4.6-tuxcare.9",
      "purl": "pkg:maven/org.springframework.boot/org.springframework.boot.gradle.plugin@2.4.6-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f88c3a9a-32a5-5f7a-9bc4-56f59d021ebe",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 2.4.6-tuxcare.9 of org.springframework.boot:org.springframework.boot.gradle.plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/org.springframework.boot.gradle.plugin@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:513b51e6-7552-51d0-8d9b-d9cb3a73c7e5",
      "id": "CVE-2023-20873",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20873 is fixed in version 2.4.6-tuxcare.9 of org.springframework.boot:org.springframework.boot.gradle.plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/org.springframework.boot.gradle.plugin@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cd35bc8-0084-5022-8c36-7b9704fdade5",
      "id": "CVE-2023-20883",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20883 is fixed in version 2.4.6-tuxcare.9 of org.springframework.boot:org.springframework.boot.gradle.plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/org.springframework.boot.gradle.plugin@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60f0c268-ee5c-5d42-8d4e-f604dbb61ff7",
      "id": "CVE-2023-34055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34055 is fixed in version 2.4.6-tuxcare.9 of org.springframework.boot:org.springframework.boot.gradle.plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/org.springframework.boot.gradle.plugin@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c21b7485-4ba8-5b6d-a246-fbbecb0b6313",
      "id": "CVE-2023-38286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-38286 affects version 2.4.6-tuxcare.9 of org.springframework.boot:org.springframework.boot.gradle.plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/org.springframework.boot.gradle.plugin@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79634294-dd8a-5f71-8ee7-e43e3c8d3ffd",
      "id": "CVE-2024-38807",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38807 is fixed in version 2.4.6-tuxcare.9 of org.springframework.boot:org.springframework.boot.gradle.plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/org.springframework.boot.gradle.plugin@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0609dc8-8b8c-5e52-b9a0-b62ff922ad3b",
      "id": "CVE-2025-22235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22235 is fixed in version 2.4.6-tuxcare.9 of org.springframework.boot:org.springframework.boot.gradle.plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/org.springframework.boot.gradle.plugin@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3278bc5d-f778-57b6-90c7-dd9f4a874c69",
      "id": "CVE-2026-22733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22733 is fixed in version 2.4.6-tuxcare.9 of org.springframework.boot:org.springframework.boot.gradle.plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/org.springframework.boot.gradle.plugin@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e80a01e5-86d8-5484-b7a9-32d25ecf1fb2",
      "id": "CVE-2026-40972",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40972 is fixed in version 2.4.6-tuxcare.9 of org.springframework.boot:org.springframework.boot.gradle.plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/org.springframework.boot.gradle.plugin@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4b100f7-4167-5b0f-964c-9cd41566ef70",
      "id": "CVE-2026-40973",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40973 is fixed in version 2.4.6-tuxcare.9 of org.springframework.boot:org.springframework.boot.gradle.plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/org.springframework.boot.gradle.plugin@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a939a93-7c66-503e-8f5f-94106bd02f72",
      "id": "CVE-2026-40974",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40974 is fixed in version 2.4.6-tuxcare.9 of org.springframework.boot:org.springframework.boot.gradle.plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/org.springframework.boot.gradle.plugin@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15a8c2ab-3d19-5aab-aae9-3c8010918012",
      "id": "CVE-2026-40975",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40975 is fixed in version 2.4.6-tuxcare.9 of org.springframework.boot:org.springframework.boot.gradle.plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/org.springframework.boot.gradle.plugin@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e489967c-5ee2-5a2a-b01c-60fa520390a4",
      "id": "CVE-2026-40977",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40977 is fixed in version 2.4.6-tuxcare.9 of org.springframework.boot:org.springframework.boot.gradle.plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/org.springframework.boot.gradle.plugin@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:179a5649-6fa5-5e94-a135-1b91b0e89da6",
      "id": "CVE-2026-40992",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40992 affects version 2.4.6-tuxcare.9 of org.springframework.boot:org.springframework.boot.gradle.plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/org.springframework.boot.gradle.plugin@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89e25693-dacf-514d-9f17-c507ebd12f4f",
      "id": "CVE-2026-41001",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41001 affects version 2.4.6-tuxcare.9 of org.springframework.boot:org.springframework.boot.gradle.plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/org.springframework.boot.gradle.plugin@2.4.6-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.boot/org.springframework.boot.gradle.plugin@2.4.6-tuxcare.9"
    }
  ]
}