{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:91305963-e68b-57dc-a2d5-21bb0487bd01",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.boot/spring-boot-starter-thymeleaf@2.4.6-tuxcare.8",
      "type": "library",
      "group": "org.springframework.boot",
      "name": "spring-boot-starter-thymeleaf",
      "version": "2.4.6-tuxcare.8",
      "purl": "pkg:maven/org.springframework.boot/spring-boot-starter-thymeleaf@2.4.6-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b1d16198-f97a-59fc-ad49-fa9200c1d9f9",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-thymeleaf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-thymeleaf@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dca82df3-2aff-5c9e-b0bc-f544efbcbd68",
      "id": "CVE-2023-20873",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20873 is fixed in version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-thymeleaf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-thymeleaf@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50cf984b-913e-52b7-93cc-a291501c4429",
      "id": "CVE-2023-20883",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20883 is fixed in version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-thymeleaf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-thymeleaf@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfc87a17-bbe8-523c-92cb-39a965938099",
      "id": "CVE-2023-34055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34055 is fixed in version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-thymeleaf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-thymeleaf@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bcbb644-d939-5a90-9f72-cc96a11f5c8f",
      "id": "CVE-2023-38286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-38286 affects version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-thymeleaf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-thymeleaf@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9144cf88-8e63-5a9a-87ca-bb8d9ea14504",
      "id": "CVE-2024-38807",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38807 is fixed in version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-thymeleaf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-thymeleaf@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f33af626-7ac9-57c1-bd09-c30f5017d21d",
      "id": "CVE-2025-22235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22235 is fixed in version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-thymeleaf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-thymeleaf@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f29e25f-13d5-5a86-ba0d-65c743ceabf0",
      "id": "CVE-2026-22733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22733 is fixed in version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-thymeleaf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-thymeleaf@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13bc3c4e-da30-5b15-bf78-3224436ae3d2",
      "id": "CVE-2026-40972",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40972 is fixed in version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-thymeleaf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-thymeleaf@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5700b171-efd6-5e48-ab00-fe6703527909",
      "id": "CVE-2026-40973",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40973 is fixed in version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-thymeleaf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-thymeleaf@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89ceee0d-bd8e-5839-b9d3-45862298bcb3",
      "id": "CVE-2026-40974",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40974 is fixed in version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-thymeleaf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-thymeleaf@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27e6e8ff-4216-5542-9d85-49366eaf1706",
      "id": "CVE-2026-40975",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40975 is fixed in version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-thymeleaf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-thymeleaf@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae96f079-3b06-5a12-87c7-35982f09e3fe",
      "id": "CVE-2026-40977",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40977 is fixed in version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-thymeleaf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-thymeleaf@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52d99ded-ab51-52e6-ab69-b3faa44a2fe0",
      "id": "CVE-2026-40992",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40992 affects version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-thymeleaf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-thymeleaf@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a83524c6-390e-5459-8bca-b28bbad4d562",
      "id": "CVE-2026-41001",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41001 affects version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-thymeleaf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-thymeleaf@2.4.6-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-thymeleaf@2.4.6-tuxcare.8"
    }
  ]
}