{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6232b83e-9e3e-5eff-95c9-1cbbb141b9d2",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web@2.7.16-tuxcare.9",
      "type": "library",
      "group": "org.springframework.boot",
      "name": "spring-boot-starter-web",
      "version": "2.7.16-tuxcare.9",
      "purl": "pkg:maven/org.springframework.boot/spring-boot-starter-web@2.7.16-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:98c63f7e-9148-5bba-a022-da48d466a9ee",
      "id": "CVE-2023-34055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34055 is fixed in version 2.7.16-tuxcare.9 of org.springframework.boot:spring-boot-starter-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web@2.7.16-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53fade8a-2eb0-5b5e-a6f7-5c0dbc7d9466",
      "id": "CVE-2023-38286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-38286 affects version 2.7.16-tuxcare.9 of org.springframework.boot:spring-boot-starter-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web@2.7.16-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80f33cd5-8f00-5e7e-a24c-4c24f8b41b3b",
      "id": "CVE-2024-38807",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38807 is fixed in version 2.7.16-tuxcare.9 of org.springframework.boot:spring-boot-starter-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web@2.7.16-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fd584b2-7b96-5e6b-996b-ee2f16753cf5",
      "id": "CVE-2025-22235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22235 is fixed in version 2.7.16-tuxcare.9 of org.springframework.boot:spring-boot-starter-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web@2.7.16-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61e72aaf-7d71-57a6-90fd-c6c9ad3ae27b",
      "id": "CVE-2026-22733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22733 is fixed in version 2.7.16-tuxcare.9 of org.springframework.boot:spring-boot-starter-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web@2.7.16-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b474e95c-dd17-5a6e-a637-7f290755e230",
      "id": "CVE-2026-40972",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40972 is fixed in version 2.7.16-tuxcare.9 of org.springframework.boot:spring-boot-starter-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web@2.7.16-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:863dc1cf-3fc5-5c62-9d23-71f51ae459bc",
      "id": "CVE-2026-40973",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40973 is fixed in version 2.7.16-tuxcare.9 of org.springframework.boot:spring-boot-starter-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web@2.7.16-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59324cf6-1d23-5a65-9cde-3979160627c3",
      "id": "CVE-2026-40974",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40974 is fixed in version 2.7.16-tuxcare.9 of org.springframework.boot:spring-boot-starter-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web@2.7.16-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:205ab70c-e69b-58ef-b02f-db0cf2c95fc1",
      "id": "CVE-2026-40975",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40975 is fixed in version 2.7.16-tuxcare.9 of org.springframework.boot:spring-boot-starter-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web@2.7.16-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04f4e626-bc42-567c-8995-361f88a8d0b6",
      "id": "CVE-2026-40977",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40977 is fixed in version 2.7.16-tuxcare.9 of org.springframework.boot:spring-boot-starter-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web@2.7.16-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a51e52f4-6c4b-5253-b52f-2c6623a57b44",
      "id": "CVE-2026-40992",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40992 affects version 2.7.16-tuxcare.9 of org.springframework.boot:spring-boot-starter-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web@2.7.16-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5027ee3-83de-555c-8c39-6f957d0b1312",
      "id": "CVE-2026-41001",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41001 is fixed in version 2.7.16-tuxcare.9 of org.springframework.boot:spring-boot-starter-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web@2.7.16-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-web@2.7.16-tuxcare.9"
    }
  ]
}