{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8bcb00a1-7a4b-522a-9bc1-9f0cd2cafe10",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.struts/struts2-core@2.5.33-tuxcare.1",
      "type": "library",
      "group": "org.apache.struts",
      "name": "struts2-core",
      "version": "2.5.33-tuxcare.1",
      "purl": "pkg:maven/org.apache.struts/struts2-core@2.5.33-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:428b258b-1676-5299-a1f4-cb53be519b5c",
      "id": "CVE-2016-3093",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-3093 does not affect version 2.5.33-tuxcare.1 of org.apache.struts:struts2-core. not_affected \u2014 Target uses OGNL 3.1.29, which is much newer than the vulnerable versions (< 3.0.12). The vulnerability CVE-2016-3093 stems from improper method reference caching in OGNL before version 3.0.12, causing denial of service through resource exhaustion. The fix was introduced in OGNL 3.0.12 and Struts upgraded to OGNL 3.1.12 in October 2016 (commit 8699f639f). The target's OGNL 3.1.29 includes all f..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.struts/struts2-core@2.5.33-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a28b071b-f52c-5122-83c8-8d3cb81a9429",
      "id": "CVE-2018-1327",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1327 affects version 2.5.33-tuxcare.1 of org.apache.struts:struts2-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.struts/struts2-core@2.5.33-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a2c9ff0-9c75-52c8-92ac-1e2409adbb0f",
      "id": "CVE-2024-53677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-53677 is fixed in version 2.5.33-tuxcare.1 of org.apache.struts:struts2-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.struts/struts2-core@2.5.33-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:027ae794-e0b5-5f8b-931b-7805b0cef1db",
      "id": "CVE-2025-64775",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64775 affects version 2.5.33-tuxcare.1 of org.apache.struts:struts2-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.struts/struts2-core@2.5.33-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c572e0d-6c63-56d6-a0aa-083091804152",
      "id": "CVE-2025-66675",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66675 affects version 2.5.33-tuxcare.1 of org.apache.struts:struts2-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.struts/struts2-core@2.5.33-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a2841ee-85dc-5c0f-badb-f77c13b70e57",
      "id": "CVE-2025-68493",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-68493 affects version 2.5.33-tuxcare.1 of org.apache.struts:struts2-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.struts/struts2-core@2.5.33-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:684c69c2-da3a-5495-b792-47acc57d5000",
      "id": "CVE-2026-73633",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73633 affects version 2.5.33-tuxcare.1 of org.apache.struts:struts2-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.struts/struts2-core@2.5.33-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.struts/struts2-core@2.5.33-tuxcare.1"
    }
  ]
}