{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:072d92e9-7435-5433-8550-9773fc1e6ab7",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jdbc",
      "version": "5.3.27-tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:888e0bcd-e421-5a4a-a365-1403b5c8ede8",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f3e612f-4dda-5d83-955e-639c41fda6b1",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1749f8f7-2b35-5f6b-9cd4-ce44e754ad2d",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb609385-ad8c-50fd-9060-bc42519274fa",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cf24317-fd9b-5ab4-951f-3fddf6548eba",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:831a0c0b-d6ed-53b4-9f5b-76358c0df65b",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a658f0a0-c2c0-52e2-869b-099ba3f52fe6",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d831ae22-36ed-5dac-8f5a-677ab6c737db",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:477dc097-fa81-5eb4-b3b7-ef169531ccd9",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c77d36b-7b28-5a61-9d33-e451a3e0dc6a",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed4a94e7-6702-5a3f-b40d-07e2cb4c7d97",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dc3579c-c5a7-594c-8d08-3acb2ff1c831",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-jdbc 5.3.27-tuxcare.6."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbb0c404-1fd5-56fe-b16a-54c4ad5052cf",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:530b5358-98ad-59e9-8056-af1a2eb1d635",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:325af390-8a92-5a51-b2dd-c39477f39070",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e148d84b-f79c-5460-9300-c3dde598ccd3",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be9367cd-2763-597b-b3b6-9bbcde6f5384",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:926279c2-b4a9-5b0d-a210-65c002cddef0",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16274e5e-ce58-5938-b08b-e79dbc070ae5",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c03294b8-3c40-5187-80fd-0bb22aa04288",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d8ae022-9993-5dff-b960-9115d17b0508",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69fc255f-646a-5d03-841f-19469617dd58",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83a4f8d8-98fd-5d72-917d-7780b6e98d03",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41840. The vulnerability was previously addressed through backport commits for CVE-2026-22740, which applied the identical doOnDiscard cleanup logic to prevent resource exhaustion from multipart request processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fd9c2bf-98f0-5b9a-bee8-dd23cc8be759",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fbeb3e1-eca2-5f9e-9188-a7b32d4d3543",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2571d77-3c26-50e2-a02e-e5962ce4e85f",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f23953c-12a1-5a09-b8a4-ac073935e4b3",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:620db75b-75c9-500f-a54c-1b25d851332e",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29766ca8-5fe1-58eb-bbd8-127a85dba9a6",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18d8d4f2-aaf2-5f13-91a1-b3ca6e3b8a12",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5133202-acfa-506a-874e-7bae3b6e13e3",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:356e7404-8384-53f8-9a9a-198c993e3670",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14d63bb0-858b-5aa5-9591-a0fabbe60023",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4908051c-7a04-5565-af9b-4547b567ad03",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8af6f5c-dfdb-5a18-bcf3-15b23761f902",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:542e0ad3-1ddd-5929-92f6-89ea0075926d",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ba29217-1aff-5f9b-9f87-5f0ec499562e",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.27-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.6"
    }
  ]
}