{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2f632b00-e057-552d-86fb-6494f9358c27",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jcl",
      "version": "5.3.31-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7221af2e-c32d-582c-81f2-bc9ef7dd11f1",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a950726e-1299-5dc8-bc4f-6e3228ae9e90",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02c0cb55-90ae-52cf-8b3a-b7f4ef04c09c",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb5b35b8-0fd9-5ab6-95cb-9b940bd47a47",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80b782ce-630b-522c-b63e-ecae8f84be08",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fc4c482-399c-5e7b-9833-e07b43146a50",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2203908-b648-5f01-8cc4-c3fe0d9820df",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e75d4ec-e39c-512f-9d32-91fa63a29f79",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53e02780-146d-581b-9b38-fbeb685d4c01",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9d8c3aa-514c-5a2d-89c8-4ac8907c962f",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a159934e-dcae-577d-9b46-02a4ef747745",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb28888d-98dc-5dc2-8b19-b150ed8ff6ec",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-jcl 5.3.31-tuxcare.8."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a524a6e-529e-5bc7-ab77-ade05d2f651e",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65916f40-ddc4-5e8e-ab61-9357c483cf29",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c13a2ac6-2988-5418-865b-d4a2d29178cb",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:510800a4-2dd1-50fe-a576-4679ff268a16",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:213ffa3c-bc23-5358-b375-4c8639b8bc22",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc08b572-d62e-5e43-9d02-6c4bc2d5920b",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcc893b6-5cc2-5534-ad9f-005205d72ce3",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e4d9b98-e830-53a6-af5f-21b99730f5c1",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72115169-03d7-5354-b7cd-5a63b427b0e0",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b3f174b-a7b2-5c93-b4c6-1dd0ed4ee285",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ad34fa7-c376-5e62-88ce-d3fd81f647f6",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.8 of org.springframework:spring-jcl. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df907259-63b7-5fcc-b212-8c3e2f83147c",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f06bda4-1aae-50bf-b681-ca9536a202e7",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5639f97c-93c7-57f9-8129-505f7b2073d1",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a30e0e6-0e30-54a6-b7d1-a3e95130a392",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:606464f9-f72b-5b56-8f4c-8d4bf2227b9c",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2c7b334-88b7-5f77-bdd4-b424cc20aa68",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4848596-8afd-5b9b-ba76-ae430aa6436f",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:059e1ce4-0d77-565c-b852-c22b95c23e97",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a21ee6d8-f2f1-5c47-b8ea-61fc882133e6",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebafa621-1fe4-5877-8cc4-eae3e3cdb9cc",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a98033e1-6b24-5485-9cd8-50a0263eef45",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03b1b452-8f2f-5d31-adf0-55e45f275101",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:746bc73a-e96f-590a-a060-55842327695f",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c3e4ef1-c9bc-570a-ac09-de51c4a8af31",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jcl@5.3.31-tuxcare.8"
    }
  ]
}