{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e9266afb-e1b4-5d89-982e-7a6d4c23eeb8",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jetty@2.6.15-tuxcare.4",
      "type": "library",
      "group": "org.springframework.boot",
      "name": "spring-boot-starter-jetty",
      "version": "2.6.15-tuxcare.4",
      "purl": "pkg:maven/org.springframework.boot/spring-boot-starter-jetty@2.6.15-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4ef3082c-1734-50d9-80ce-a4ed38181290",
      "id": "CVE-2023-34055",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34055 affects version 2.6.15-tuxcare.4 of org.springframework.boot:spring-boot-starter-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jetty@2.6.15-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5787332f-d8ba-51f4-ac98-52b7e6bd2b4c",
      "id": "CVE-2024-38807",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38807 affects version 2.6.15-tuxcare.4 of org.springframework.boot:spring-boot-starter-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jetty@2.6.15-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac7d26c8-6390-56aa-ae0a-79e7a78eeef9",
      "id": "CVE-2025-22235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22235 is fixed in version 2.6.15-tuxcare.4 of org.springframework.boot:spring-boot-starter-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jetty@2.6.15-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3ff06dc-cb66-5bca-b396-dd9056169866",
      "id": "CVE-2026-22733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22733 affects version 2.6.15-tuxcare.4 of org.springframework.boot:spring-boot-starter-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jetty@2.6.15-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1946b049-f5c9-5ae6-8ea5-8a133bd00dc5",
      "id": "CVE-2026-40972",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40972 affects version 2.6.15-tuxcare.4 of org.springframework.boot:spring-boot-starter-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jetty@2.6.15-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf4ea944-3797-53b8-9e16-a68a1650609c",
      "id": "CVE-2026-40973",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40973 affects version 2.6.15-tuxcare.4 of org.springframework.boot:spring-boot-starter-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jetty@2.6.15-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c58f796-b7b7-5a11-8160-250d8546f135",
      "id": "CVE-2026-40974",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40974 affects version 2.6.15-tuxcare.4 of org.springframework.boot:spring-boot-starter-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jetty@2.6.15-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7763c6d-5c56-5a27-851a-59e81ebe6a33",
      "id": "CVE-2026-40975",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40975 affects version 2.6.15-tuxcare.4 of org.springframework.boot:spring-boot-starter-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jetty@2.6.15-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae79d69f-aee1-53b1-9ea4-5aa4dea0aca9",
      "id": "CVE-2026-40977",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40977 affects version 2.6.15-tuxcare.4 of org.springframework.boot:spring-boot-starter-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jetty@2.6.15-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jetty@2.6.15-tuxcare.4"
    }
  ]
}