{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fc1f9dae-593d-5c8e-9920-f6de0a61f33a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jdbc",
      "version": "5.3.37-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:064f9914-a7ed-54a1-81af-20e96156b1fb",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5834989-c6c6-51a2-a9f9-b5fc366bb4df",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94d8c24c-7595-5b2f-8c1c-c29f3201023b",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61e985c0-9d79-588e-9c93-f526db0ac328",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d94297c-bd16-5bbe-98e4-577c7c4eb124",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:205aaa68-e73c-585c-88f9-0654bed54024",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e89da95-d4af-5350-9767-c3cf25f20732",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5778257d-5e7f-53c9-8a56-76fbfdefe547",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:492c2219-9314-5bfb-a53a-9b1c747f23af",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7164aff-06e0-58ee-a2a0-9656ae03dd51",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b257714-70c1-5f6b-a546-93d64ab325eb",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5fe1254-8a71-5c9c-8559-c40e6c363c4e",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5651d741-794a-588c-a87d-4e1efbe0ae0e",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79f983c0-18a7-5787-83d5-dddde80b290f",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42030649-f17d-5928-b893-fc4f1e035bc2",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43a220a5-b043-5095-ad3d-59a1cf6422d4",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fd15133-4458-595d-8131-c25668115f88",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cdee36b-b236-53fb-b625-5a5ca2559e74",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d510360-120e-53e3-b1bc-3fd162bb330b",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04774a46-700b-5d0a-b95a-4cf6bfe732ec",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60fb0c4d-5d49-59d3-805d-d15459581f7c",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ac0a533-64d8-5f4e-b483-f79f2310a190",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d03a8c95-013e-5e96-8149-a757df37d6da",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:238f653c-8fdf-5525-9423-f5bd1112f354",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3174aace-3960-53b6-b6bc-24b2b7974233",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ac8b7b6-aa85-56f8-88d6-24b05fe193fd",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19e4b42c-4784-5d6b-a55c-39910d8d19c2",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa4a52ff-0759-5a31-a9b1-3a3ccf22b7f3",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d37be6e-6774-5d2e-9e4b-bb333d157203",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75d8564c-5d61-53e8-97a9-9d73066acbd8",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29267bc4-aab3-5db4-ba19-50a1636a0020",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c11322df-9d48-5530-b823-0d9b9e33ca44",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2da4c837-1442-50ec-992b-f8b57d8e3ac4",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.4"
    }
  ]
}