{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:622d7cda-0452-5b2b-a900-8a7cd4e9cfc1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-aop",
      "version": "5.3.31-tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:8d05e33f-e232-5928-8e39-0f4111aed710",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75c6d507-ae34-5b99-af0d-6a65b92b7a24",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e9c2446-6776-56ce-83b3-df2c54ebd28b",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8180406b-9156-5ac6-bdf6-7c71f93143c3",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bab4d7de-218b-51c1-88a4-cfd4064756be",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83bcb95a-bee1-5914-b04c-b2317f8f2588",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d075431-9f11-55da-9b26-0090a0432257",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ec3555c-19b3-576f-b0ee-1a268d3a18b1",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bf66e92-ce53-5a7f-ac75-2408856da281",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83570d4f-553b-588f-9c2b-f785446005d0",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b267da83-0ec5-5699-ab09-cb698498fa4e",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63840236-a26b-56de-8a48-e8eb658c9ce7",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-aop 5.3.31-tuxcare.6."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a77e4c8a-5da9-5546-a8e3-610a82f2c2be",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea76fd3b-4743-5ba8-8874-d7802c417507",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20699184-773f-59f3-9c71-fedd3bd3759a",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40b068f6-14a0-5e47-a7c0-2ba55497137b",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce489387-3127-5f5c-bf48-8c9875527448",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c09a750d-0846-554d-b7a4-c176bbb58b0c",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ce9984f-09bd-528f-a35d-c4f2a3db569c",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e87873b-1e61-512d-ae96-74c08e0f3b23",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b760e1d7-4fc8-51cc-a506-a0143f0c873a",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27c9980b-9de8-558b-b1d8-e59e73d632b7",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15ae6bb0-c1d4-5dbe-9b94-2d3fd625faae",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.6 of org.springframework:spring-aop. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44fa6a6b-b89c-5575-a4c4-fa3549877b27",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7e49769-4191-5ca1-ab1d-c0ba52840128",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a30cf54-88d7-570a-854f-7217cba4970f",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdee2ce5-b032-50e7-9130-336eeb479309",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd164733-2735-53f7-a57c-053199185a67",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4fbb564-f09d-5fbc-8ecc-d5795f675899",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed41f533-1c03-5b55-929d-80be0ee3a924",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1eef680-c6ab-5343-b147-1f25f181b47a",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33d00859-b246-5d33-8c4b-f3ffb58d6df8",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e99ff7cd-765c-5ab4-ba65-ff54ab28797e",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97526a47-7066-5169-9da5-eb0456f08b97",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a186cbb2-ed7f-5fab-ac77-ee2211ad2bff",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e689710f-2ba2-5194-aa44-08a2532eb3fd",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03629de1-f92f-505e-bf1b-a7214ad8db1e",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.31-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.6"
    }
  ]
}