{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:af7d9f24-d41e-51c6-be75-bfdf9fe58582",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-aspects",
      "version": "5.3.39-tuxcare.15",
      "purl": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:969470c0-d565-5999-be49-aa1e22fca055",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42e55fea-2bb7-5a78-8ecd-eb87f70b544d",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.15 of org.springframework:spring-aspects. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4471e5c-1d54-527c-9f72-73887aad32ee",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d87032d-f640-51c2-ae28-47d2580e6e17",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8faaa8c-f9b9-5950-a010-5e4a3cf6f0c1",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:942d6685-7267-535e-9121-b3e8f377498e",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1b0750a-a0ba-5b89-baef-343b72461e57",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c586cf6f-18d4-504c-8684-57a208d075ed",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-aspects 5.3.39-tuxcare.15."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35332446-c2c0-5e9f-9c2b-f567089ce409",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f86de2b-f719-5a85-81c4-1247dd5141f6",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb7208ff-c7d1-546e-b031-714e39ba3d9a",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fe171d4-03c0-5cac-b355-e5ab050f9b1e",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e06569e-1342-53e8-bc6d-eff829f0651d",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86a986bf-2d6c-599e-a187-2aa4ad1ddf6c",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b866dd29-1ab3-5e86-9e4b-81c3a3eb1cfe",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec1f44a0-e84b-5763-9c7b-581c5be9d48d",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91e2ab14-1182-5566-beec-1d98faae6002",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad950b19-bc73-5a50-8bb6-eaa460d6b607",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b03b478-7e59-5c6a-80f7-f7fad29817f7",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.15 of org.springframework:spring-aspects. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c8e389a-27b2-5a00-b2b0-b36d55277c24",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c10dbf3e-14eb-5896-9c35-ecf424755d78",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24aae5ff-b2ab-580e-b512-680c8185d35c",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c83537e-c4b5-56b8-affc-afa4ade425c0",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5ffe472-297e-5ce2-84b4-bb31f57c9573",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa1b87ba-ee91-5df4-8d66-e31cc1bfc61e",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad7224e6-1d3b-545c-8129-7885aa2cb927",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20ee66ec-fd50-5a9d-accd-d5d000a83c66",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43afd828-b571-5663-b726-145c512e86fd",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84fa1f0d-f7d3-5cb7-a23c-787a18e171bc",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ae73dd7-f5b8-5811-b1ee-4b253a1e64e7",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81cd3f53-3b3c-5327-a8ac-97858584b705",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02c3ad61-a4bc-5507-98ae-1e392d63c17f",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a250861-5e6f-55da-969a-10293606c56e",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.15 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aspects@5.3.39-tuxcare.15"
    }
  ]
}