{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:96561b56-dc54-5279-ac14-6abb0374891f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.amqp/spring-amqp-dist@2.4.17-tuxcare.4",
      "type": "library",
      "group": "org.springframework.amqp",
      "name": "spring-amqp-dist",
      "version": "2.4.17-tuxcare.4",
      "purl": "pkg:maven/org.springframework.amqp/spring-amqp-dist@2.4.17-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7ed838e8-ecfc-5953-bc9c-46db1ead3a27",
      "id": "CVE-2018-11087",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-11087 does not affect version 2.4.17-tuxcare.4 of org.springframework.amqp:spring-amqp-dist. not_affected \u2014 The target Spring AMQP 2.4.17-tuxcare.4 is not affected by CVE-2018-11087 (lack of hostname verification in TLS connections). The upstream vendor (Spring/Pivotal) applied the fix in version 2.1.0.M3 (commit 444b74e9), making hostname verification enabled by default. The target's base version 2.4.17 already contains this upstream fix. The vulnerable pattern (missing hostname verification) is not..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.amqp/spring-amqp-dist@2.4.17-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e107503-ec48-537f-b34b-82b5da65da92",
      "id": "CVE-2026-41701",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41701 affects version 2.4.17-tuxcare.4 of org.springframework.amqp:spring-amqp-dist."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.amqp/spring-amqp-dist@2.4.17-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78a2759d-7575-58f7-a4a5-4df9f1e8cc92",
      "id": "CVE-2026-41714",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41714 affects version 2.4.17-tuxcare.4 of org.springframework.amqp:spring-amqp-dist."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.amqp/spring-amqp-dist@2.4.17-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a7d4b42-06ce-5c12-8650-d488087438cf",
      "id": "CVE-2026-47860",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47860 affects version 2.4.17-tuxcare.4 of org.springframework.amqp:spring-amqp-dist."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.amqp/spring-amqp-dist@2.4.17-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b57262b5-2679-5500-9279-7f0ac3b9454f",
      "id": "CVE-2026-59271",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59271 affects version 2.4.17-tuxcare.4 of org.springframework.amqp:spring-amqp-dist."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.amqp/spring-amqp-dist@2.4.17-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9adba6f-ebd3-5cbf-a6c4-cb63d911f463",
      "id": "CVE-2026-59272",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59272 affects version 2.4.17-tuxcare.4 of org.springframework.amqp:spring-amqp-dist."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.amqp/spring-amqp-dist@2.4.17-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5724745f-0fb6-57e4-91cf-b0e5be9a1e41",
      "id": "CVE-2026-59275",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59275 affects version 2.4.17-tuxcare.4 of org.springframework.amqp:spring-amqp-dist."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.amqp/spring-amqp-dist@2.4.17-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.amqp/spring-amqp-dist@2.4.17-tuxcare.4"
    }
  ]
}