{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:46b64215-fe6b-54a1-89cf-4d513072e058",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jersey@2.3.6.RELEASE-tuxcare.2",
      "type": "library",
      "group": "org.springframework.boot",
      "name": "spring-boot-starter-jersey",
      "version": "2.3.6.RELEASE-tuxcare.2",
      "purl": "pkg:maven/org.springframework.boot/spring-boot-starter-jersey@2.3.6.RELEASE-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:18854528-465f-57c4-91b9-827cb19230ce",
      "id": "CVE-2023-20873",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20873 is fixed in version 2.3.6.RELEASE-tuxcare.2 of org.springframework.boot:spring-boot-starter-jersey."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jersey@2.3.6.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d8be4c7-7463-51b7-baef-21d838b021d7",
      "id": "CVE-2023-20883",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20883 is fixed in version 2.3.6.RELEASE-tuxcare.2 of org.springframework.boot:spring-boot-starter-jersey."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jersey@2.3.6.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:301cd276-dc3f-5578-a5b9-f02630428a6a",
      "id": "CVE-2023-34055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34055 is fixed in version 2.3.6.RELEASE-tuxcare.2 of org.springframework.boot:spring-boot-starter-jersey."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jersey@2.3.6.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffcd91ee-4b81-51de-b0e3-8958b25dd985",
      "id": "CVE-2023-38286",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-38286 is a false positive for org.springframework.boot:spring-boot-starter-jersey 2.3.6.RELEASE-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jersey@2.3.6.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c53edf80-5005-5e5d-a688-4f14470ec1b2",
      "id": "CVE-2024-38807",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38807 affects version 2.3.6.RELEASE-tuxcare.2 of org.springframework.boot:spring-boot-starter-jersey."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jersey@2.3.6.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8db246d-cbed-50a3-9458-dc3e2437278c",
      "id": "CVE-2025-22235",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22235 affects version 2.3.6.RELEASE-tuxcare.2 of org.springframework.boot:spring-boot-starter-jersey."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jersey@2.3.6.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c14145d-9658-513b-9be5-43c800df2f98",
      "id": "CVE-2026-22733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22733 affects version 2.3.6.RELEASE-tuxcare.2 of org.springframework.boot:spring-boot-starter-jersey."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jersey@2.3.6.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f98b2615-4bdc-528b-960a-3aedb3716658",
      "id": "CVE-2026-40972",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40972 affects version 2.3.6.RELEASE-tuxcare.2 of org.springframework.boot:spring-boot-starter-jersey."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jersey@2.3.6.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77132840-90c9-52e8-8396-87b6b0a0ef50",
      "id": "CVE-2026-40973",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40973 affects version 2.3.6.RELEASE-tuxcare.2 of org.springframework.boot:spring-boot-starter-jersey."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jersey@2.3.6.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d17cea18-c97f-527a-96c0-042cfc9eb310",
      "id": "CVE-2026-40974",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40974 affects version 2.3.6.RELEASE-tuxcare.2 of org.springframework.boot:spring-boot-starter-jersey."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jersey@2.3.6.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80f9a4df-00a6-51d3-8267-90b5cdbaf69f",
      "id": "CVE-2026-40975",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40975 affects version 2.3.6.RELEASE-tuxcare.2 of org.springframework.boot:spring-boot-starter-jersey."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jersey@2.3.6.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87747b44-1fc4-51bc-b51b-9a5da20f288f",
      "id": "CVE-2026-40977",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40977 affects version 2.3.6.RELEASE-tuxcare.2 of org.springframework.boot:spring-boot-starter-jersey."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jersey@2.3.6.RELEASE-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jersey@2.3.6.RELEASE-tuxcare.2"
    }
  ]
}