{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b12ae925-94f8-5c2d-8817-9fd32039eb9a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-aop",
      "version": "5.3.39-tuxcare.15",
      "purl": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ac430441-7bfe-5fbd-84b6-bb2288ba9229",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63c0efde-7b2e-51cf-be5f-9083343b4109",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.15 of org.springframework:spring-aop. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5daf5016-a3b7-5ee7-9316-26c5c9662199",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd7a7dc9-7b36-5159-99c6-04a5ce5e6ca0",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84baca7a-0e5e-5934-99ba-1aae1093e06e",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc7d1530-2be3-5610-a8ba-37a49016cc42",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3038712-0460-54f2-8c58-7e6782675927",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0aa8f9ef-261f-55ed-894b-5e98e74a74f7",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-aop 5.3.39-tuxcare.15."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3052d66e-2b62-5cf1-9ad4-e820704227df",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e5215f4-df10-51a7-b241-8db9c1cef8c2",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ffa29ec-0fff-562c-a74c-14a716124f69",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6da619d-139c-5260-83b8-38465b6f8f2d",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c3f4407-4b5d-5e0d-9475-b1cd1088645e",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e069885-7e6f-50dc-bc92-32ce81ac740d",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff566d06-b7f9-548d-9b62-da71cb459562",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2432f443-0d55-5cb6-ac6c-f7c807f03cda",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc48b9b2-070e-52c7-a441-a4c8cef6a575",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b991585-07ee-531b-889c-e0e0215005ac",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bf36045-e7a4-5611-8b01-f67dadabf8e9",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.15 of org.springframework:spring-aop. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:892480ec-6d22-5c3d-b718-68741bf48dd5",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9006c859-e381-56aa-a0bb-38d743b7fc87",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c565037-5f10-5b0e-bcce-1b3ce7018143",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d1da30b-c7ce-582f-a433-00b590d1f9d2",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07b25f32-7864-53e1-9fbd-e540a726f4a3",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f275c09c-cf30-53aa-a23a-d6b663adb9e5",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54db6348-0b42-5083-89b2-8b562ffd495b",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cea66bd-8d07-5015-a76d-cdd7d08d763b",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c862f67-15ad-56fb-8dd5-cbb0eb538524",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ba4aeb7-c607-5819-9b18-1048336584d5",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:474193b4-8577-5e69-b7c4-59ab2b02426f",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f969ff36-9f9f-5ba8-a5f9-5fe9e72e4a6c",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d63fc96a-7ead-5472-920f-5b165db70795",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df52be60-e467-5bbf-baf9-b50296315080",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.15 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aop@5.3.39-tuxcare.15"
    }
  ]
}