{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9fd2dc3f-a7c0-5da8-a7e1-9c6fa4ff708b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.boot/spring-boot-configuration-metadata@2.7.16-tuxcare.8",
      "type": "library",
      "group": "org.springframework.boot",
      "name": "spring-boot-configuration-metadata",
      "version": "2.7.16-tuxcare.8",
      "purl": "pkg:maven/org.springframework.boot/spring-boot-configuration-metadata@2.7.16-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:12dfc34b-37c1-5ede-9136-20f8865ca7ab",
      "id": "CVE-2023-34055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34055 is fixed in version 2.7.16-tuxcare.8 of org.springframework.boot:spring-boot-configuration-metadata."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-configuration-metadata@2.7.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa1b64ce-8969-5c32-b025-409efe2d4729",
      "id": "CVE-2023-38286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-38286 affects version 2.7.16-tuxcare.8 of org.springframework.boot:spring-boot-configuration-metadata."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-configuration-metadata@2.7.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17c889a9-ba72-5bb7-959c-7132bfacfeb7",
      "id": "CVE-2024-38807",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38807 is fixed in version 2.7.16-tuxcare.8 of org.springframework.boot:spring-boot-configuration-metadata."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-configuration-metadata@2.7.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fad0ecb9-2db3-529f-92cb-74d1cba77464",
      "id": "CVE-2025-22235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22235 is fixed in version 2.7.16-tuxcare.8 of org.springframework.boot:spring-boot-configuration-metadata."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-configuration-metadata@2.7.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9a7a251-a32a-5a41-9e7f-1fdcb0f68baf",
      "id": "CVE-2026-22733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22733 is fixed in version 2.7.16-tuxcare.8 of org.springframework.boot:spring-boot-configuration-metadata."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-configuration-metadata@2.7.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4dce74c2-1689-5680-b572-88794f1ae09a",
      "id": "CVE-2026-40972",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40972 is fixed in version 2.7.16-tuxcare.8 of org.springframework.boot:spring-boot-configuration-metadata."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-configuration-metadata@2.7.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8767c93c-b075-5baf-a6f6-41c3c5ffacb0",
      "id": "CVE-2026-40973",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40973 is fixed in version 2.7.16-tuxcare.8 of org.springframework.boot:spring-boot-configuration-metadata."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-configuration-metadata@2.7.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a91b7c68-41c4-562f-805c-958bf697df99",
      "id": "CVE-2026-40974",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40974 is fixed in version 2.7.16-tuxcare.8 of org.springframework.boot:spring-boot-configuration-metadata."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-configuration-metadata@2.7.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:538ffad6-7636-5de1-8d7b-6b3430b4f50b",
      "id": "CVE-2026-40975",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40975 is fixed in version 2.7.16-tuxcare.8 of org.springframework.boot:spring-boot-configuration-metadata."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-configuration-metadata@2.7.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:797030b7-7afb-502e-bc0e-83c295a47240",
      "id": "CVE-2026-40977",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40977 is fixed in version 2.7.16-tuxcare.8 of org.springframework.boot:spring-boot-configuration-metadata."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-configuration-metadata@2.7.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21bd61a0-4124-546c-8ee5-cb8009baef37",
      "id": "CVE-2026-40992",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40992 affects version 2.7.16-tuxcare.8 of org.springframework.boot:spring-boot-configuration-metadata."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-configuration-metadata@2.7.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e44d5f4d-df7f-5e4c-ba44-46a42c654dfb",
      "id": "CVE-2026-41001",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41001 is fixed in version 2.7.16-tuxcare.8 of org.springframework.boot:spring-boot-configuration-metadata."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-configuration-metadata@2.7.16-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.boot/spring-boot-configuration-metadata@2.7.16-tuxcare.8"
    }
  ]
}