{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e5bc45d1-8d3d-58ab-b167-b9de4d6da06a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.amqp/spring-rabbit-test@2.4.17.tuxcare",
      "type": "library",
      "group": "org.springframework.amqp",
      "name": "spring-rabbit-test",
      "version": "2.4.17.tuxcare",
      "purl": "pkg:maven/org.springframework.amqp/spring-rabbit-test@2.4.17.tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1311dcf0-dc88-508f-9f9a-91d22fceb19e",
      "id": "CVE-2018-11087",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-11087 does not affect version 2.4.17.tuxcare of org.springframework.amqp:spring-rabbit-test. not_affected \u2014 The target Spring AMQP 2.4.17-tuxcare.4 is not affected by CVE-2018-11087 (lack of hostname verification in TLS connections). The upstream vendor (Spring/Pivotal) applied the fix in version 2.1.0.M3 (commit 444b74e9), making hostname verification enabled by default. The target's base version 2.4.17 already contains this upstream fix. The vulnerable pattern (missing hostname verification) is not..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.amqp/spring-rabbit-test@2.4.17.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2f2eab3-7e97-5d4f-b4dc-ba3aad7cea8b",
      "id": "CVE-2026-41701",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41701 affects version 2.4.17.tuxcare of org.springframework.amqp:spring-rabbit-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.amqp/spring-rabbit-test@2.4.17.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b39d9a3e-759b-56b1-b5d9-c2997798926a",
      "id": "CVE-2026-41714",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41714 affects version 2.4.17.tuxcare of org.springframework.amqp:spring-rabbit-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.amqp/spring-rabbit-test@2.4.17.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4669cf2c-1b64-50de-a9bd-1181f8f43ba7",
      "id": "CVE-2026-47860",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47860 affects version 2.4.17.tuxcare of org.springframework.amqp:spring-rabbit-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.amqp/spring-rabbit-test@2.4.17.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51bf712c-ae5c-59b2-b00b-26ccd954292a",
      "id": "CVE-2026-59271",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59271 affects version 2.4.17.tuxcare of org.springframework.amqp:spring-rabbit-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.amqp/spring-rabbit-test@2.4.17.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:337af58b-fa37-59e5-881d-619e04f2dc11",
      "id": "CVE-2026-59272",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59272 affects version 2.4.17.tuxcare of org.springframework.amqp:spring-rabbit-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.amqp/spring-rabbit-test@2.4.17.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a635adb-c958-52f5-937e-484670fe6669",
      "id": "CVE-2026-59275",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59275 affects version 2.4.17.tuxcare of org.springframework.amqp:spring-rabbit-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.amqp/spring-rabbit-test@2.4.17.tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.amqp/spring-rabbit-test@2.4.17.tuxcare"
    }
  ]
}