{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:51e13cb9-d449-5a9f-ae9d-e2c1c1bba61e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jms",
      "version": "4.1.9.RELEASE-tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:fc50e51e-2c2e-5ac6-bfb2-dd894645e220",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad92ce05-ac1c-5afb-a4a4-1c0d0b85be6c",
      "id": "CVE-2016-5007",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-5007 affects version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19dde027-debf-53bf-8bbc-c30d4fdb5391",
      "id": "CVE-2018-1257",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-1257 does not affect version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms. not_affected \u2014 Spring Framework version 4.1.9.RELEASE is not affected by CVE-2018-1257. The vulnerability requires the selector header feature with Spring EL expression parsing in STOMP subscriptions, which was introduced in version 4.2.0.RC1 (April 2015). Version 4.1.9.RELEASE predates this feature and contains no SpEL expression parsing in the messaging/websocket modules, making the ReDoS attack vector impo..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b421ba5-898e-526a-9a07-5a4cd2161baf",
      "id": "CVE-2018-1270",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-1270 does not affect version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms. not_affected \u2014 Spring Framework version 4.1.9.RELEASE is not affected by CVE-2018-1270. The vulnerability exists in the selector header feature that uses SpEL expression evaluation, which was introduced in version 4.2.0.RC1. Version 4.1.9.RELEASE predates this feature and does not contain any of the vulnerable code paths."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:346e0782-be1e-53a4-a83f-df3a80d47e49",
      "id": "CVE-2018-1271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1271 is fixed in version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de7bd2fe-0dc4-5317-9171-5db000976d04",
      "id": "CVE-2018-1272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1272 is fixed in version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:033b5947-5f6c-5f35-a469-9ffdce691b09",
      "id": "CVE-2018-1275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-1275 does not affect version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms. not_affected \u2014 Spring Framework 4.1.9.RELEASE is not affected by CVE-2018-1275. The vulnerable selector expression feature that enables SpEL injection was introduced in Spring Framework 4.2. Version 4.1.9 predates this feature entirely and does not process subscription selector expressions."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4201d49a-7f41-5c9b-b5d3-5553cdb451f6",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-5421 does not affect version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms. already_fixed \u2014 The target repository (Spring Framework 4.1.9.RELEASE) already contains the essential fix for CVE-2020-5421. The UrlPathHelper.removeSemicolonContent() method ensures jsessionid path parameters are always stripped from request URIs, even when removeSemicolonContent is set to false. This prevents attackers from using jsessionid path parameters to bypass RFD (Reflected File Download) attack prote..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb9e262b-0f94-549f-b8d4-c3ac9efd4521",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97bebc8e-6790-5b54-ae73-1246e26864ad",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-22118 does not affect version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms. not_affected \u2014 Spring Framework 4.1.9.RELEASE is not affected by CVE-2021-22118. The vulnerability specifically affects WebFlux multipart handling in Spring 5.2.x < 5.2.15 and 5.3.x < 5.3.7. WebFlux was introduced in Spring 5.0, and Spring 4.1.9 predates this component entirely. The target uses Servlet API-based multipart handling via Apache Commons FileUpload with servlet container-managed temp directories, ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e92204c-0c09-5433-ba87-49721fdb5b09",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:371af1ea-e707-50ce-a491-e72a3c8650b6",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e8084d9-3a66-5b2b-bf09-ea5b106e1c88",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c93001e-79d2-57ce-b294-bce97147b02d",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24a7957e-e671-5e5e-8362-1c5b528826d3",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06c64928-37ae-57ad-9bb7-1f7f863b5205",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:814b61bc-56b2-5c44-b3c5-ca1dad9638bd",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39e325e8-6d6f-57f6-8422-7a3fb8ae7b99",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:191a3b73-ec00-50bf-a79f-e8e3db0720af",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11ec2958-62bd-55bc-aac5-6093de00bdf4",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d90015d-c685-510b-a964-bcc89d636000",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8adf720-b12a-57ae-a5f0-5c05b3b513e9",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38809 does not affect version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms. not_affected \u2014 Version 4.1.9.RELEASE is not affected by CVE-2024-38809. The vulnerable regex pattern ETAG_HEADER_VALUE_PATTERN that causes catastrophic backtracking DoS does not exist in this version. ETag parsing uses simple string operations (equals, split) that process input in linear time."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a6c006d-2783-55e8-9004-50ee39b462a2",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a44c4884-dd45-5dac-ab0b-92c6d7b5993c",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22347361-392a-5c8e-a9be-3c94a4f7daf0",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:739fe431-7d6a-5d1b-af01-2e1272d62d49",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9ace8a9-dc73-5e75-add1-a22510383e78",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5dafc3f7-2548-5491-b208-ac778db596e1",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28b3c49a-5197-52bc-9642-5011014b3475",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 4.1.9.RELEASE-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jms@4.1.9.RELEASE-tuxcare.1"
    }
  ]
}