{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e2bde1e0-996e-57a3-8daa-833dd45e4aaa",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jdbc",
      "version": "5.3.37-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:cd754270-0912-56c2-b75d-b3e7967be7dc",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9977f37-0322-53aa-882b-0b9de20324b0",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30815916-8e9b-557b-9dd7-4752a684ef36",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62191b1f-89a4-5325-89cc-f57f26ec37fa",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a092ebe-838e-5e46-b4f7-a417987eab0f",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2250bad-fa87-545f-b488-4e1ab3040367",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b93de70-5e82-57bb-b7e5-05c07047fb43",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5686a991-24eb-52c6-9700-2b74f91351f0",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5261760a-eee6-5701-921f-84b71ccb4023",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b49863f5-f19f-5d7c-98ff-25def74511ba",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73eb6cd3-aaba-538f-a12f-c852c1cf2fde",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec26ed3b-b4db-5c87-a96c-6218219efd11",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b406bf34-0449-53be-8352-5d434c3576eb",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07231801-5a13-58f2-8614-632a4eb41afd",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:990a3da1-ac41-51a1-a672-5b5084297891",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a828a482-2d8a-5821-ae5e-a2f3e63d1818",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a1c804c-4599-5da0-9524-918649d884ec",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfe31063-4622-5bf5-a165-0f32ebd96ae9",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e00fb226-1a45-5eaf-a8f1-ccf743ac1798",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66ee2a14-b9cf-5d7f-8bba-5b58a11af3c1",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46a54221-a07d-52c1-b75a-5d2094a582e2",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a1ce62a-8a7b-5ca2-9db1-78ff8ae720a3",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f781f592-e178-5a94-8d8e-35fac894f546",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86358ce7-1dcd-5300-94e8-6df66dec8e5d",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a32fe30a-d16f-5df9-82d8-46f07bbf4c77",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4710153-1d8a-5ecd-a00b-2c12d448aeda",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cad2ee2b-380b-5c14-941b-dbba470e3a1c",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b3471e6-a05f-5f8c-9852-401a73526553",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de2499ea-e91c-5468-af21-f24c0445731c",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a10e0cb-7a63-51f4-874f-ac6bbe211ec7",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63fc5db4-a0e3-5ac8-af52-a62931aabbee",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2385fe54-2e08-5f6a-a707-ad7eda9964c6",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc8446df-7a2a-5c0c-a074-33a40784a7d4",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.3"
    }
  ]
}