{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1a203ca6-ff32-5aa9-893e-1e2a93c7ab81",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-cassandra-reactive@2.5.15-tuxcare.1",
      "type": "library",
      "group": "org.springframework.boot",
      "name": "spring-boot-starter-data-cassandra-reactive",
      "version": "2.5.15-tuxcare.1",
      "purl": "pkg:maven/org.springframework.boot/spring-boot-starter-data-cassandra-reactive@2.5.15-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:3bfc3448-412f-534d-a1da-37732ca229d7",
      "id": "CVE-2023-34055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34055 is fixed in version 2.5.15-tuxcare.1 of org.springframework.boot:spring-boot-starter-data-cassandra-reactive."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-cassandra-reactive@2.5.15-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f548f53f-9a83-5eb4-89bb-a067d9f2528a",
      "id": "CVE-2024-38807",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38807 is fixed in version 2.5.15-tuxcare.1 of org.springframework.boot:spring-boot-starter-data-cassandra-reactive."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-cassandra-reactive@2.5.15-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95fe3763-919b-54dd-b8a7-096a0756923a",
      "id": "CVE-2025-22235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22235 is fixed in version 2.5.15-tuxcare.1 of org.springframework.boot:spring-boot-starter-data-cassandra-reactive."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-cassandra-reactive@2.5.15-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2409e1b4-ac0f-5c7f-87b0-4bc8c5e6c293",
      "id": "CVE-2026-22733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22733 is fixed in version 2.5.15-tuxcare.1 of org.springframework.boot:spring-boot-starter-data-cassandra-reactive."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-cassandra-reactive@2.5.15-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57bf4eb5-0483-52a9-b5b4-53bc7f373e66",
      "id": "CVE-2026-40972",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40972 is fixed in version 2.5.15-tuxcare.1 of org.springframework.boot:spring-boot-starter-data-cassandra-reactive."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-cassandra-reactive@2.5.15-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f1ae0ec-d364-5751-ac36-0af0069c5400",
      "id": "CVE-2026-40973",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40973 is fixed in version 2.5.15-tuxcare.1 of org.springframework.boot:spring-boot-starter-data-cassandra-reactive."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-cassandra-reactive@2.5.15-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df9c7cab-4d25-5523-bbfe-e4f2937ed6d9",
      "id": "CVE-2026-40974",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40974 affects version 2.5.15-tuxcare.1 of org.springframework.boot:spring-boot-starter-data-cassandra-reactive."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-cassandra-reactive@2.5.15-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e39bda30-38a3-5a5b-b790-b7afe6016eab",
      "id": "CVE-2026-40975",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40975 affects version 2.5.15-tuxcare.1 of org.springframework.boot:spring-boot-starter-data-cassandra-reactive."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-cassandra-reactive@2.5.15-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e728d311-edd0-5a66-8e24-c4bb368a6393",
      "id": "CVE-2026-40977",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40977 affects version 2.5.15-tuxcare.1 of org.springframework.boot:spring-boot-starter-data-cassandra-reactive."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-cassandra-reactive@2.5.15-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75d493bb-3dd0-5de1-a5df-c4f59f148961",
      "id": "CVE-2026-40992",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-40992 does not affect version 2.5.15-tuxcare.1 of org.springframework.boot:spring-boot-starter-data-cassandra-reactive. not_affected \u2014 Version 2.5.15 is NOT AFFECTED by CVE-2026-40992. The vulnerability requires the automatic SSL configuration feature (Ssl class) introduced in Spring Boot 3.4+. Version 2.5.15 lacks this feature entirely - it has no autoconfiguration code that automatically enables SSL for mail, and therefore no insecure default. All SSL configuration in 2.5.15 must be done manually via spring.mail.properties.*..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-cassandra-reactive@2.5.15-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdf393d5-b799-5d78-a897-e22f15306e1a",
      "id": "CVE-2026-41001",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41001 affects version 2.5.15-tuxcare.1 of org.springframework.boot:spring-boot-starter-data-cassandra-reactive."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-cassandra-reactive@2.5.15-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-cassandra-reactive@2.5.15-tuxcare.1"
    }
  ]
}