{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c6b4a5e9-6dcc-51bf-95e5-218f737af3ef",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-aop",
      "version": "5.3.31-tuxcare.9",
      "purl": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:adc27f45-037b-59bc-9ec5-98a315055297",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4105ac1-b3f5-56c4-9228-c73bb9be0935",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62f3d4fc-2f04-555a-9a39-745dc9f3ab8f",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fb8bedf-a5da-548f-a952-39a48a797b5f",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebd52179-2ec3-59b2-92ee-346f8f350101",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ba05024-294f-5152-8d70-3bd6e633ec8d",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23615e55-a0ad-54d0-b289-29168cce2ef5",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d60b1ed-a4c4-5fbd-a612-02ae667d75d1",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31ba99c6-fae4-5409-9e0c-e7520eff3514",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1288262-3bb3-5e08-87c9-d6c25704b04a",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d4c36f7-b18a-58c3-874a-d6aee5357143",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9678e951-85a9-583b-a8aa-28c385183f30",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-aop 5.3.31-tuxcare.9."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b11b301a-30d3-5e39-89bc-439950f4eeb0",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce3200b3-8ee8-5f8f-88ac-49e01e2e54bb",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3db31198-0c78-50ac-94d4-d70fa9d940ca",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24c3f490-9ce6-5c73-bec4-f60c0d6e4909",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:235bc739-4d03-5348-a579-fc4bee50d622",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9d989da-cf8f-524c-b23a-e1bc730dc02f",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fd884f0-020c-5704-97d8-71d39efbfc1e",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0f74962-3c67-5389-b63d-348f376d5de5",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa3c604c-58cd-5046-9b42-260f467c6bb2",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96956729-261f-5430-a5fa-8730d6041308",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abd08c26-a06d-50a2-9ac8-09e017d79e5c",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.9 of org.springframework:spring-aop. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2999f95c-cc82-57ee-937a-f9208f4e6a82",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c494aa69-00c0-5f7f-8aad-f08eb2c1ab61",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61072c6f-c889-597b-809a-009cc5c3cf77",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69c64151-a1f9-52ad-97d3-fe5f6fe23615",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49e58c35-7ed6-5d2d-9195-15f68a4b4fe4",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90cf4e92-0c8b-5a9b-a387-6e9b92d84724",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96d24f38-6462-5deb-b43e-de37722decbd",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42ac5474-f7b4-582d-b6f5-d5da769045e7",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c03245d1-8485-508c-9919-3b0f50aeb145",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fc3e846-a52a-51e3-88aa-bae76222e1e7",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea8cd46d-bd70-5346-a4bc-b1e0b646f7ad",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89a57c69-3eaf-55c4-8bac-27ea32719577",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6555499-3d76-5479-96a6-422e32a14be8",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8182abaa-9eca-5c21-b6d9-f4b27cec4d68",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.9"
    }
  ]
}