{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b876c555-42cd-5363-bb98-fb451d1baebe",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jms",
      "version": "5.3.37-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:3ba6509c-69a9-541c-84fd-caa8b4476f4c",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11efdd5c-6993-5717-80ad-61842453267c",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad8a6a2e-4c4c-5b93-b1df-b3d16e6b2322",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49bd04a4-76bc-5c7a-ae7f-9852dda70973",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5dfbdfbd-9568-5174-8441-a8a52d3937c8",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a04c132-c2ab-52fe-bcaf-47b5f633652b",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f72ae60-0778-53d3-9171-69217d84c18e",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcee9ac6-7a32-51d3-bb8b-ef248cc41025",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b34cca65-1a8f-573f-8dcb-1f7b7e00b0f1",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6432347-7360-5a98-bf97-4afb49e9b690",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3aa60f62-3436-56b4-b5ff-a5e95d22f535",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72a306bc-3194-5d79-95df-82c03c5fb8fb",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47c3c924-3ad8-5a2c-9bd6-f9d78de7e98b",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18bbd24a-9ede-5f7f-91f0-e12fe7fdb8a7",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c755fd7a-5c19-5d63-928a-2f11ae9ed772",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e8998f2-d54f-5f04-895f-12fe8a634b63",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31001df0-71a1-5cc5-bb6f-d52614671fa2",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0d58ecd-86bc-5c1d-8f09-624822fac458",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25c4beba-0840-537e-9207-a0babcc42cba",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.2 of org.springframework:spring-jms. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:575e0442-1d3d-57fb-975c-40ac244652ba",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b98edb92-92ad-5f1e-bdd0-e3e5c890a8f1",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7e94b37-c786-55ec-aa49-c17db6255f57",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d05ea8f5-d05b-5c69-9cb3-43e4eee3c576",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06049f9d-7512-5b52-b013-ae8b71668195",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88878d8e-e1ae-55de-8796-41e89bd0bc70",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56674423-700f-59ab-b222-a2b76c9de7ea",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d771768b-7e14-5d8e-a3b4-4a9b519056e6",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84ff4fdf-9e97-57e8-b815-d22ac90c0976",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.2 of org.springframework:spring-jms. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6536018c-421f-59fe-a9f9-d48a5b41dde6",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8401d07-bb5e-5733-8bc7-1102955c8930",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da96dba5-09b0-57e3-bd7c-3c03bc3d4cb9",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55dc65a8-7c35-55d3-a8f7-54032bc034b5",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27277562-9b18-557f-86f1-3d52b35d808b",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.2"
    }
  ]
}