{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1e77c225-5047-51b3-83c6-71b82e9de9bd",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.boot/spring-boot-starter-parent@2.4.6-tuxcare.7",
      "type": "library",
      "group": "org.springframework.boot",
      "name": "spring-boot-starter-parent",
      "version": "2.4.6-tuxcare.7",
      "purl": "pkg:maven/org.springframework.boot/spring-boot-starter-parent@2.4.6-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ea8d9229-05fe-5afc-b82b-901f08426b9c",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-parent@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea6b6736-32ae-5b2a-b4e9-b9aea163a79f",
      "id": "CVE-2023-20873",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20873 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-parent@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31ac561f-e77c-5c89-a09e-f580e649252d",
      "id": "CVE-2023-20883",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20883 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-parent@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:639533f1-525f-5a86-9c50-ec3bcf2f5ecd",
      "id": "CVE-2023-34055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34055 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-parent@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffc5117d-1c87-5eea-8548-cdc0c93dee9f",
      "id": "CVE-2023-38286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-38286 affects version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-parent@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cc54d69-998d-5b82-bfaf-ee33a590b560",
      "id": "CVE-2024-38807",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38807 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-parent@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:170b8e3b-856e-538a-9fdf-295490acb7d4",
      "id": "CVE-2025-22235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22235 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-parent@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b2b7fe0-589d-5ff8-9d8c-40e4ebcbbb34",
      "id": "CVE-2026-22733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22733 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-parent@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c976150-70ed-57e5-8175-1992c71f5ef2",
      "id": "CVE-2026-40972",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40972 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-parent@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44764338-680e-592f-8e9b-6d416ae5a14d",
      "id": "CVE-2026-40973",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40973 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-parent@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c46282c3-e574-5099-8a0f-dd9b6d20dd5f",
      "id": "CVE-2026-40974",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40974 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-parent@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89afc9e1-fb4d-5f52-b182-5e485e7d8dd6",
      "id": "CVE-2026-40975",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40975 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-parent@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de9b5064-ae07-5070-a275-0329cccaebfd",
      "id": "CVE-2026-40977",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40977 is fixed in version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-parent@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c9d5a37-f061-5833-bf2e-0c6327858f9d",
      "id": "CVE-2026-40992",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40992 affects version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-parent@2.4.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba003d35-5c71-59f8-859e-796015dab7a3",
      "id": "CVE-2026-41001",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41001 affects version 2.4.6-tuxcare.7 of org.springframework.boot:spring-boot-starter-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-parent@2.4.6-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-parent@2.4.6-tuxcare.7"
    }
  ]
}