{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8ab16f21-61da-57f1-b5ae-092db5d689d4",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.boot/spring-boot-starter-freemarker@2.4.6-tuxcare.7",
      "type": "library",
      "group": "org.springframework.boot",
      "name": "spring-boot-starter-freemarker",
      "version": "2.4.6-tuxcare.7",
      "purl": "pkg:maven/org.springframework.boot/spring-boot-starter-freemarker@2.4.6-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:12dc9484-ba78-5615-9c7a-a1068f91bcd3",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-freemarker."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-freemarker@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9197bac0-fc8a-52db-bbfc-59409c0435f6",
      "id": "CVE-2023-20873",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20873 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-freemarker."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-freemarker@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:283d5b22-1c65-5552-a5b5-8fd75cf1b79e",
      "id": "CVE-2023-20883",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20883 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-freemarker."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-freemarker@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81b4110f-7230-5327-b762-16477d20ebb4",
      "id": "CVE-2023-34055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34055 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-freemarker."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-freemarker@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:502b9fb3-1fb8-5127-8664-dda1b4beea30",
      "id": "CVE-2023-38286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-38286 affects version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-freemarker."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-freemarker@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2bd27d1-971f-5e83-96de-2e12cff799ac",
      "id": "CVE-2024-38807",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38807 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-freemarker."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-freemarker@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bfd0a89-e1ec-53de-af6e-228a0da76013",
      "id": "CVE-2025-22235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22235 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-freemarker."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-freemarker@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c8b9d8f-f14e-5448-85b3-f8d00a6103c9",
      "id": "CVE-2026-22733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22733 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-freemarker."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-freemarker@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39d0ac9e-1db6-50da-a381-1126ef31d8d3",
      "id": "CVE-2026-40972",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40972 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-freemarker."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-freemarker@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a5b798a-2103-50aa-9ffe-e4a08dc6f681",
      "id": "CVE-2026-40973",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40973 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-freemarker."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-freemarker@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1995ea65-54b3-574a-9b2c-afffc2581630",
      "id": "CVE-2026-40974",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40974 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-freemarker."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-freemarker@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f0ff58b-d3f9-575a-83b1-9cd346a8f420",
      "id": "CVE-2026-40975",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40975 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-freemarker."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-freemarker@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cce8e1e-c1dd-5521-87ee-a580f37170bd",
      "id": "CVE-2026-40977",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40977 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-freemarker."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-freemarker@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05952192-40fc-57c5-8243-1f71a2d4936b",
      "id": "CVE-2026-40992",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40992 affects version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-freemarker."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-freemarker@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92214a4a-29ae-514f-adaa-8e060a5a3446",
      "id": "CVE-2026-41001",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41001 affects version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-freemarker."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-freemarker@2.4.6-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-freemarker@2.4.6-tuxcare.7"
    }
  ]
}