{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:37848ad1-27e0-5c55-8266-1546249d432d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.boot/spring-boot-starter-json@2.4.6-tuxcare.7",
      "type": "library",
      "group": "org.springframework.boot",
      "name": "spring-boot-starter-json",
      "version": "2.4.6-tuxcare.7",
      "purl": "pkg:maven/org.springframework.boot/spring-boot-starter-json@2.4.6-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:aa451f5f-df75-5a8a-8da6-60a0cb8a9ebe",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-json."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-json@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff50870a-689a-5185-8101-1a75ed44c943",
      "id": "CVE-2023-20873",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20873 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-json."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-json@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c953d709-67f0-54b0-bb3e-3e6c5b162856",
      "id": "CVE-2023-20883",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20883 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-json."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-json@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2be49a89-25be-5d09-80c3-391ae988a196",
      "id": "CVE-2023-34055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34055 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-json."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-json@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bd8c81f-6538-53bb-9a0c-1706bd6f34c8",
      "id": "CVE-2023-38286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-38286 affects version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-json."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-json@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8233dd0-9de7-54a7-83b1-420de4ddda61",
      "id": "CVE-2024-38807",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38807 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-json."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-json@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63333c92-59aa-54a4-a987-1a40f8782457",
      "id": "CVE-2025-22235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22235 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-json."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-json@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:135275bb-879a-5e1d-9dd5-88a60cc7f330",
      "id": "CVE-2026-22733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22733 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-json."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-json@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9dca06b-01d5-5695-920e-020d6ed9f5c2",
      "id": "CVE-2026-40972",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40972 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-json."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-json@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4911170c-4f3a-5ccc-a85c-8a92b6bd0e25",
      "id": "CVE-2026-40973",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40973 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-json."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-json@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4566d57-512f-577f-b23e-4c94e15f1dd6",
      "id": "CVE-2026-40974",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40974 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-json."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-json@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e292c9ce-8544-5ee1-880e-d18626a137ea",
      "id": "CVE-2026-40975",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40975 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-json."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-json@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:600a6333-e2e4-5ed1-987c-c8ae870acd06",
      "id": "CVE-2026-40977",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40977 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-json."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-json@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0786bd7c-5510-5294-923a-cb87d21276f4",
      "id": "CVE-2026-40992",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40992 affects version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-json."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-json@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1debc9d9-16e8-5cb0-892a-c260bb9a64ef",
      "id": "CVE-2026-41001",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41001 affects version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-json."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-json@2.4.6-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-json@2.4.6-tuxcare.7"
    }
  ]
}