{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f4f0b255-4ded-52d8-ae08-eda23c076e36",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.boot/spring-boot-maven-plugin@2.4.6-tuxcare.6",
      "type": "library",
      "group": "org.springframework.boot",
      "name": "spring-boot-maven-plugin",
      "version": "2.4.6-tuxcare.6",
      "purl": "pkg:maven/org.springframework.boot/spring-boot-maven-plugin@2.4.6-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:dbdb5e94-2584-5b1a-9c50-d909183e0688",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-maven-plugin@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1c99d7f-bf39-5711-a77f-bd847c5d46d7",
      "id": "CVE-2023-20873",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20873 is fixed in version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-maven-plugin@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9640a89-6105-5107-8964-ccf5b1d5d39b",
      "id": "CVE-2023-20883",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20883 is fixed in version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-maven-plugin@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87c2b285-5133-5d8c-8d64-2865079b5850",
      "id": "CVE-2023-34055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34055 is fixed in version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-maven-plugin@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3fb91f9-72e2-53e1-954f-bcf31d20f5d0",
      "id": "CVE-2023-38286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-38286 affects version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-maven-plugin@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71912c1c-4214-5cdf-9a6c-9d74a4969641",
      "id": "CVE-2024-38807",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38807 affects version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-maven-plugin@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d519abe0-7905-5f67-8ac2-97f36d4853f9",
      "id": "CVE-2025-22235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22235 is fixed in version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-maven-plugin@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b75c5c49-7fcc-5024-a24b-eaa2ab91e1a6",
      "id": "CVE-2026-22733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22733 is fixed in version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-maven-plugin@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bc0df74-6d1a-5ec4-9855-d6c83ed79a90",
      "id": "CVE-2026-40972",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40972 is fixed in version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-maven-plugin@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6664916-6b50-519f-866f-cd2692f736cf",
      "id": "CVE-2026-40973",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40973 is fixed in version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-maven-plugin@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1346f5e6-6a48-5ef0-abfa-60cb911e52fe",
      "id": "CVE-2026-40974",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40974 is fixed in version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-maven-plugin@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67fd0076-25da-5ae4-8309-0be73d334f50",
      "id": "CVE-2026-40975",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40975 is fixed in version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-maven-plugin@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3be0de69-6060-53a7-8ce4-0f29774344eb",
      "id": "CVE-2026-40977",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40977 is fixed in version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-maven-plugin@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d5e07e0-8ba4-5b13-874d-671aabec5729",
      "id": "CVE-2026-40992",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40992 affects version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-maven-plugin@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:637070c8-8660-5c3e-bbf7-f4e750540d8f",
      "id": "CVE-2026-41001",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41001 affects version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-maven-plugin@2.4.6-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.boot/spring-boot-maven-plugin@2.4.6-tuxcare.6"
    }
  ]
}