{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4162751a-71ea-51bf-a764-000a3c20cadc",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.boot/spring-boot-starter-security@2.4.6-tuxcare.9",
      "type": "library",
      "group": "org.springframework.boot",
      "name": "spring-boot-starter-security",
      "version": "2.4.6-tuxcare.9",
      "purl": "pkg:maven/org.springframework.boot/spring-boot-starter-security@2.4.6-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c911d793-f4c7-5792-acb6-2b858571ef5a",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 2.4.6-tuxcare.9 of org.springframework.boot:spring-boot-starter-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-security@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61cf0411-84d8-537e-b169-32aa2054cd98",
      "id": "CVE-2023-20873",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20873 is fixed in version 2.4.6-tuxcare.9 of org.springframework.boot:spring-boot-starter-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-security@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c31ed48-3426-5a37-9225-0c8563982c55",
      "id": "CVE-2023-20883",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20883 is fixed in version 2.4.6-tuxcare.9 of org.springframework.boot:spring-boot-starter-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-security@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33fafdd9-f742-5f14-9286-f5beb4d45e25",
      "id": "CVE-2023-34055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34055 is fixed in version 2.4.6-tuxcare.9 of org.springframework.boot:spring-boot-starter-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-security@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3010812f-6f39-5fbc-8eae-1b202872e5b7",
      "id": "CVE-2023-38286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-38286 affects version 2.4.6-tuxcare.9 of org.springframework.boot:spring-boot-starter-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-security@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a42c18c-67a7-5bb8-9abe-33acfd0a0f64",
      "id": "CVE-2024-38807",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38807 is fixed in version 2.4.6-tuxcare.9 of org.springframework.boot:spring-boot-starter-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-security@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73e0695c-4c18-5194-a49c-78d1274eb0f3",
      "id": "CVE-2025-22235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22235 is fixed in version 2.4.6-tuxcare.9 of org.springframework.boot:spring-boot-starter-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-security@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b3c045b-ae8e-5353-a567-145b3ad72f05",
      "id": "CVE-2026-22733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22733 is fixed in version 2.4.6-tuxcare.9 of org.springframework.boot:spring-boot-starter-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-security@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:527dfb7b-ee0f-520b-b3c3-584bb0acad28",
      "id": "CVE-2026-40972",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40972 is fixed in version 2.4.6-tuxcare.9 of org.springframework.boot:spring-boot-starter-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-security@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5896358f-9188-50be-9d54-cb6a3ba6b894",
      "id": "CVE-2026-40973",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40973 is fixed in version 2.4.6-tuxcare.9 of org.springframework.boot:spring-boot-starter-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-security@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66342dd4-9124-572a-9b03-18a6039d8d15",
      "id": "CVE-2026-40974",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40974 is fixed in version 2.4.6-tuxcare.9 of org.springframework.boot:spring-boot-starter-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-security@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e781d7f-c44f-5c12-8c61-7de17ccf590a",
      "id": "CVE-2026-40975",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40975 is fixed in version 2.4.6-tuxcare.9 of org.springframework.boot:spring-boot-starter-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-security@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83eccdaf-ab82-569c-a300-7ebba9db9824",
      "id": "CVE-2026-40977",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40977 is fixed in version 2.4.6-tuxcare.9 of org.springframework.boot:spring-boot-starter-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-security@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac1fdd0a-4e73-57e9-877c-3e85897152a6",
      "id": "CVE-2026-40992",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40992 affects version 2.4.6-tuxcare.9 of org.springframework.boot:spring-boot-starter-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-security@2.4.6-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac492715-7c64-5b0c-8a94-537c6d4ac830",
      "id": "CVE-2026-41001",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41001 affects version 2.4.6-tuxcare.9 of org.springframework.boot:spring-boot-starter-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-security@2.4.6-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-security@2.4.6-tuxcare.9"
    }
  ]
}