{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b8565472-93bc-5125-8abb-09987f5ade6b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web-services@2.4.6-tuxcare.8",
      "type": "library",
      "group": "org.springframework.boot",
      "name": "spring-boot-starter-web-services",
      "version": "2.4.6-tuxcare.8",
      "purl": "pkg:maven/org.springframework.boot/spring-boot-starter-web-services@2.4.6-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:22bc0b85-75d9-5659-8fa9-0ec1a095bc2b",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-web-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web-services@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b58bb417-e190-537f-a952-02163ea739df",
      "id": "CVE-2023-20873",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20873 is fixed in version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-web-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web-services@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8343a77-98dc-500c-87d5-20027055376a",
      "id": "CVE-2023-20883",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20883 is fixed in version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-web-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web-services@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51064bca-251e-5b56-95df-4587b0cda8bd",
      "id": "CVE-2023-34055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34055 is fixed in version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-web-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web-services@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83e850db-624c-5a67-b58f-ab12da11fa0d",
      "id": "CVE-2023-38286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-38286 affects version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-web-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web-services@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3986113b-3b5b-50ad-ba4d-f68e24d4da4a",
      "id": "CVE-2024-38807",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38807 is fixed in version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-web-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web-services@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:692d2c9b-0e7a-55f4-aed1-63de19524344",
      "id": "CVE-2025-22235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22235 is fixed in version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-web-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web-services@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:875d73af-05b9-5406-bd4a-2ebecae7ca3b",
      "id": "CVE-2026-22733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22733 is fixed in version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-web-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web-services@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c157b86-9023-5d9d-bf78-ff343414c716",
      "id": "CVE-2026-40972",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40972 is fixed in version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-web-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web-services@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f188031c-96be-5a19-af0e-e0976a08c52e",
      "id": "CVE-2026-40973",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40973 is fixed in version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-web-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web-services@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37b22418-e289-529a-a786-aa413e7bb37c",
      "id": "CVE-2026-40974",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40974 is fixed in version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-web-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web-services@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5f210c8-69cd-5bc9-ab6c-b3de95c288d4",
      "id": "CVE-2026-40975",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40975 is fixed in version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-web-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web-services@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:315028f3-7871-5753-b121-6bbfa9a7dcb5",
      "id": "CVE-2026-40977",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40977 is fixed in version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-web-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web-services@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff1c6eab-e7d9-5193-a99a-fe214f912afe",
      "id": "CVE-2026-40992",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40992 affects version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-web-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web-services@2.4.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4e7c428-b41c-54d2-8e4e-17f9a601bbee",
      "id": "CVE-2026-41001",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41001 affects version 2.4.6-tuxcare.8 of org.springframework.boot:spring-boot-starter-web-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web-services@2.4.6-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web-services@2.4.6-tuxcare.8"
    }
  ]
}