{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:be8d3af5-72a8-5bc4-84a3-a3c540ca175a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-messaging",
      "version": "4.2.9.RELEASE-tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6fa6d989-2f3e-5608-a0ef-f522349d56ef",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-1000027 does not affect version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef8e113c-04f5-590f-a1a9-7c80c1adbdf3",
      "id": "CVE-2016-5007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-5007 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c99dfb8-9081-5d17-a86a-acc3a38d32a9",
      "id": "CVE-2016-9878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-9878 does not affect version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging. already_fixed \u2014 The target Spring Framework 4.2.9.RELEASE already contains the fix for CVE-2016-9878. The vulnerable path traversal issue in ResourceServlet.doInclude() has been mitigated by adding StringUtils.cleanPath() to normalize resource URLs before processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7f7f7f6-4788-5c60-b639-b032324bd7dd",
      "id": "CVE-2018-1257",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1257 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dda5d321-ccf4-5563-b867-2b7e27fca620",
      "id": "CVE-2018-1270",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1270 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66c86c59-8d22-5cd9-b288-2f99cb5534c0",
      "id": "CVE-2018-1271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1271 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e335735-4080-5b08-b4b1-65f59cf717e2",
      "id": "CVE-2018-1272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1272 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5234a71-ebec-5ac0-a627-435b518ffd82",
      "id": "CVE-2018-1275",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1275 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e53af1f-89ee-56f6-a69f-3803a007140b",
      "id": "CVE-2018-15756",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-15756 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22deeddf-6ceb-570b-8fb7-3dd802f5b204",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fa05a5e-b910-5a42-a9ab-cac4d7b8b2b3",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c6879bf-6433-5a84-aab7-554ced14241f",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16013869-991b-59a1-8a28-bbfcc2a7e7b6",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55fefc36-efdb-5afc-88b6-6a5dfc88930d",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e99290b4-a40f-5a86-8ed8-612dcb09bf1e",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e158a4b-1c12-5ea3-b31d-d9f5d37d65c1",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd6244a9-8f06-59cb-882b-2c799b61349d",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e0c7997-422c-5e02-aade-42fd5ca5f7a1",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75553c91-f29f-5aae-b3b6-4b274509efb0",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39eeef2d-baca-504f-8505-a2b6a37e8d0d",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a35b8cef-73d6-58c4-8561-20172c3f4844",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbc04422-b838-5d42-b1d7-5d4767a4ff7c",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90f28ce8-f1ee-5eb8-a4b1-7c68e84de055",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2654130d-a8b0-5d38-8708-55905af1609f",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38809 does not affect version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging. No ReDoS vulnerability: ETAG_HEADER_VALUE_PATTERN regex is not used in this version (introduced in 4.3.30)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfdfdd23-ff04-5166-a602-26adc9112901",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5f1bcd3-6bcc-531b-be3f-c92f39e2515c",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59269c33-e859-5c3a-8c40-0d84cf1f0ed1",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5ea6ee0-d52c-5297-ab4a-09ee90f2d75c",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44fbb485-7996-5678-b8bf-e802ad8679e9",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac56302d-f185-51a1-8c62-603ae8a5d8fe",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22f6a5e7-9f08-5bb3-b9f8-1a39ed9c5140",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f984b592-bc63-53c5-ad06-d090f85b1917",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9d12998-527c-57e0-8181-792f354815b0",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48515643-8925-5ee7-beba-05c706431b31",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc965809-b97a-5acf-a4d9-adb3dd93026c",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6ea7e9e-227c-5ec5-9bf7-a27d7ced8301",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a0ee972-5291-5541-bdd6-7ddedb098b1f",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37f8a7f1-4f32-5091-8091-ed288222feba",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f129db7-c13b-5b0f-8bbb-aeba768a546f",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d38cb54-1953-5511-bbe3-2660df2ea2e2",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a805b670-10b9-5252-8c01-69ca5e5e3796",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c0f6dd2-d3bc-5c64-b7a9-8385d6492a77",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c6c8a8a-d3c1-5f92-9487-b3e38ddbfa08",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34a334b1-5422-53a9-96f7-945098bbfb4c",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9edd49fa-2fc7-54f9-baaa-a40f15e2eb15",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging. not_affected \u2014 Spring Framework 4.2.9.RELEASE-tuxcare.3 is NOT AFFECTED by CVE-2026-41853. While the target version does process multipart requests, the specific vulnerable code path that enables multipart request smuggling appears to be tied to architectural changes introduced in Spring Framework 5.3.0+. The target version (4.2.9) predates these changes and uses a fundamentally different architecture."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53e164cc-89ba-5a64-b7f4-f464c4cea927",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-messaging@4.2.9.RELEASE-tuxcare.6"
    }
  ]
}