{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:992cbe93-423c-58ee-ac83-548bceac2691",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-aop",
      "version": "5.3.29-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e3ba9767-7ef5-5369-b262-2e6396587073",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1772b9b-7c1f-54d2-a670-9df76693f835",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35f57785-9226-58d7-aa85-1ee4959a73ab",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c822d198-15b2-5dd1-b25a-e4315f44ac93",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9495308-2b95-5820-a0a1-9db992ef1541",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72904965-bf3b-5511-a31b-0211ce27df23",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96157598-5943-5ffb-992b-483ad37d9260",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:156ccecb-6383-50dd-bf81-7964543180c5",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc3283d5-9d34-5b80-855d-c76a67694bfd",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c80ec58c-67cd-5814-81bd-6188b3899806",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29be7f68-1be9-502e-8100-8a28fb1c19ce",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e3f7071-d1f1-57f4-922c-d358c5aa068b",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-aop 5.3.29-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:988d5214-2b07-58b7-987a-1cf4f7419f45",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42723cbb-c50d-53eb-b311-0b76d99996e7",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eda7c8e4-4ed5-5479-8152-f8208fe1a247",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17bbba55-d331-5d8c-a7b6-32a015f9655a",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3455ae77-77d7-5f42-94e7-fd86931d5b66",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2afff11c-2c48-559b-a21f-2915c14cd1e5",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:870ceb33-f86a-534c-b05e-f73955409a50",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b154203f-3de0-5cb3-96e9-f8f117932687",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6af9cdc9-4227-5074-90f1-e2527249e95e",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d49e080-a78a-5ffb-ad43-c829040c7c3f",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0449f5c1-105b-5a28-a1dc-33f422e9584f",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.29-tuxcare.5 of org.springframework:spring-aop. already_fixed \u2014 The target repository (Spring Framework 5.3.29-tuxcare.4) already contains the complete fix for CVE-2026-41840. The fix was applied on 2026-05-19 as part of a TuxCare backport for CVE-2026-22740 (commit bc0026ae70c), which addresses the same multipart request DoS vulnerability with identical code changes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d090cca-ce7b-56a9-909e-7fbce09d0c1a",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e1a712a-240a-5586-b255-f77ed64985df",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:696bd0a0-2dc8-528d-b865-1b4a0113e4f2",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d464541f-0519-5039-ae45-8f92f0b09282",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62ab2484-8703-5088-95d8-66cd900156e6",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a304a42e-10b5-58e0-981a-f7ade3ec9f83",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f011de1-375f-5c8c-8315-8637c0ade688",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c77e930a-6646-539e-9779-e601df04853b",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b3db4c7-6a0b-5bde-a898-8fc9a540fad6",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a79895d-e414-57ca-95cb-3ddc53cfd9ef",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08b00e95-2237-5b1e-9192-63a49804ed60",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf32c7a1-8f1e-5386-9033-9994848245dd",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a97043aa-774f-57c1-8012-bf75102380fd",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5070b50-c1f2-5655-90ff-600e5ab24357",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.29-tuxcare.5 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aop@5.3.29-tuxcare.5"
    }
  ]
}