{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8959bc5c-883c-54fe-8ac7-4f08e01328d0",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.boot/spring-boot-starter-tomcat@2.3.6.RELEASE-tuxcare.5",
      "type": "library",
      "group": "org.springframework.boot",
      "name": "spring-boot-starter-tomcat",
      "version": "2.3.6.RELEASE-tuxcare.5",
      "purl": "pkg:maven/org.springframework.boot/spring-boot-starter-tomcat@2.3.6.RELEASE-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:75823b10-4606-5b6b-8e27-f197baf4c9fd",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22965 does not affect version 2.3.6.RELEASE-tuxcare.5 of org.springframework.boot:spring-boot-starter-tomcat. CVE-2022-22965 (Spring4Shell) is a data-binding RCE whose vulnerable code resides entirely in Spring Framework's spring-beans module (CachedIntrospectionResults). Spring Boot ships no vulnerable code for this CVE \u2014 it only dependency-manages the Spring Framework version via its BOM."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-tomcat@2.3.6.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69e843a6-8253-5f5e-8bb4-fa7f6e5714c3",
      "id": "CVE-2023-20873",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20873 is fixed in version 2.3.6.RELEASE-tuxcare.5 of org.springframework.boot:spring-boot-starter-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-tomcat@2.3.6.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e22b896-e4a6-533e-b5f8-2553ba6e69c7",
      "id": "CVE-2023-20883",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20883 is fixed in version 2.3.6.RELEASE-tuxcare.5 of org.springframework.boot:spring-boot-starter-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-tomcat@2.3.6.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdb1b681-66b8-5ecb-901f-67bbc51979f4",
      "id": "CVE-2023-34055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34055 is fixed in version 2.3.6.RELEASE-tuxcare.5 of org.springframework.boot:spring-boot-starter-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-tomcat@2.3.6.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bc0d7cc-2cbe-54e2-b0b1-7f0e11f9e32f",
      "id": "CVE-2023-38286",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-38286 is a false positive for org.springframework.boot:spring-boot-starter-tomcat 2.3.6.RELEASE-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-tomcat@2.3.6.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb23619c-1432-5143-8e73-acc73c3ff514",
      "id": "CVE-2024-38807",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38807 is fixed in version 2.3.6.RELEASE-tuxcare.5 of org.springframework.boot:spring-boot-starter-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-tomcat@2.3.6.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9c2eb1f-ba94-5952-8789-88368fc506d5",
      "id": "CVE-2025-22235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22235 is fixed in version 2.3.6.RELEASE-tuxcare.5 of org.springframework.boot:spring-boot-starter-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-tomcat@2.3.6.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3c48e81-b24e-5cf1-83f0-162293a7b1b2",
      "id": "CVE-2026-22733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22733 is fixed in version 2.3.6.RELEASE-tuxcare.5 of org.springframework.boot:spring-boot-starter-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-tomcat@2.3.6.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:715643c8-2c76-5cc4-b734-36548068da99",
      "id": "CVE-2026-40972",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40972 is fixed in version 2.3.6.RELEASE-tuxcare.5 of org.springframework.boot:spring-boot-starter-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-tomcat@2.3.6.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3b45c9d-c14c-5a8d-b7a2-21dffbeb5936",
      "id": "CVE-2026-40973",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40973 is fixed in version 2.3.6.RELEASE-tuxcare.5 of org.springframework.boot:spring-boot-starter-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-tomcat@2.3.6.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15392edb-6449-502e-8391-ba37e52e43c5",
      "id": "CVE-2026-40974",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40974 is fixed in version 2.3.6.RELEASE-tuxcare.5 of org.springframework.boot:spring-boot-starter-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-tomcat@2.3.6.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc8597c1-bb92-5427-aa34-bdd3c25da4a3",
      "id": "CVE-2026-40975",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40975 is fixed in version 2.3.6.RELEASE-tuxcare.5 of org.springframework.boot:spring-boot-starter-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-tomcat@2.3.6.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eec1f26f-3c8b-52ff-879a-b27dec623af8",
      "id": "CVE-2026-40977",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40977 is fixed in version 2.3.6.RELEASE-tuxcare.5 of org.springframework.boot:spring-boot-starter-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-tomcat@2.3.6.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c36b76c9-b23d-5786-8315-6ee8e4f6e677",
      "id": "CVE-2026-40992",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-40992 does not affect version 2.3.6.RELEASE-tuxcare.5 of org.springframework.boot:spring-boot-starter-tomcat. not_affected \u2014 Spring Boot 2.3.6.RELEASE-tuxcare.4 is not affected by CVE-2026-40992. The vulnerability affects the MailProperties.Ssl auto-configuration feature introduced in Spring Boot 3.4+, which does not exist in version 2.3.6. The target version uses a simpler architecture where mail auto-configuration only passes through user-configured JavaMail properties without actively managing SSL configuration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-tomcat@2.3.6.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38c1ef76-5ff9-5b4a-9e6f-65a199bd4fbc",
      "id": "CVE-2026-41001",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41001 is fixed in version 2.3.6.RELEASE-tuxcare.5 of org.springframework.boot:spring-boot-starter-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-tomcat@2.3.6.RELEASE-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-tomcat@2.3.6.RELEASE-tuxcare.5"
    }
  ]
}