{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:348398f8-bcbf-5b9b-b703-d4cf858d2bd7",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-resource-server@2.4.6-tuxcare.7",
      "type": "library",
      "group": "org.springframework.boot",
      "name": "spring-boot-starter-oauth2-resource-server",
      "version": "2.4.6-tuxcare.7",
      "purl": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-resource-server@2.4.6-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:18c03271-81a2-55ea-8e75-3bd1c0ec66e0",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-resource-server@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d266f327-d86e-5c64-aa75-78f5b119f348",
      "id": "CVE-2023-20873",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20873 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-resource-server@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9983b27-2b43-561d-a8c0-af7fd5066aae",
      "id": "CVE-2023-20883",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20883 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-resource-server@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2402b457-94c9-59e7-812b-cd514f924f02",
      "id": "CVE-2023-34055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34055 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-resource-server@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64c2e1cb-61a8-5960-a251-e7b96e65fc5b",
      "id": "CVE-2023-38286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-38286 affects version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-resource-server@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9bfc064-7ef3-5c53-9bd4-359bea3296dd",
      "id": "CVE-2024-38807",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38807 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-resource-server@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:063d5857-51de-5ffc-b92c-7f4c7a515483",
      "id": "CVE-2025-22235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22235 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-resource-server@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3040637-ee32-56b8-82ef-ffc86f6429b3",
      "id": "CVE-2026-22733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22733 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-resource-server@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c07df0f1-4a80-5b90-8ad0-1be13bab149a",
      "id": "CVE-2026-40972",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40972 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-resource-server@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf9a27cb-3bc3-562d-8414-40b740f42eb1",
      "id": "CVE-2026-40973",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40973 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-resource-server@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a98549de-f0bf-5a0d-8e9b-6755cb49ac42",
      "id": "CVE-2026-40974",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40974 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-resource-server@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3b3e419-1f55-5a22-baca-2322d0352872",
      "id": "CVE-2026-40975",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40975 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-resource-server@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d441022-dc27-51ab-bc2b-42e157e667d9",
      "id": "CVE-2026-40977",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40977 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-resource-server@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eab719b0-8561-5400-87c7-8becd7d2a7d9",
      "id": "CVE-2026-40992",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40992 affects version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-resource-server@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5b199ed-e2aa-5c82-bd74-593d42ef8e19",
      "id": "CVE-2026-41001",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41001 affects version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-resource-server@2.4.6-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-oauth2-resource-server@2.4.6-tuxcare.7"
    }
  ]
}