{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3a5c3a14-a20c-59f7-b7f6-af8f314bdfc8",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-messaging",
      "version": "5.3.37-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f3c2b40c-9478-52e2-a768-17b91cf39ea5",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d21716de-da00-5637-806d-e0f3c21a53fd",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:265f48bb-75a3-5c17-b509-0af309f6db28",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e233794-bcb1-5d34-a8e9-386c121c4038",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c397c689-4a27-5af2-920d-bb913dc79225",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88141ab7-4a77-5263-8a99-1245df37fd91",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64ae1605-d9e2-58da-815e-ba4ef8e1751f",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08433b79-47cd-5419-bcd4-3df132528e88",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:810fab3c-5264-5f6f-8ddb-65f1f12dabb1",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45f026df-b1c9-5f23-b413-25ac470fa479",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2faeaa84-6167-5707-a840-a2d7b83921de",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13d57583-62c9-5880-97d0-d29ead9091a7",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45c39658-5bec-5039-b05f-e196528888cd",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a75d37f8-a992-5651-b93d-801e6d1f9a1f",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56546bca-9b86-51a2-b151-beb1966e9194",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cd20955-e2d1-57bf-a5cc-220d8fb6db54",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a957787-938e-57bc-9332-d5b8d29f4de7",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7fe7b2a-b0b7-5c11-a00e-5585cdb68cfe",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46b7e845-b2aa-5d56-9fa9-d26d4b53d94a",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.2 of org.springframework:spring-messaging. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5432d30-c3c0-5c84-aa03-ec146915a4de",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8d1c016-2384-5770-b58e-fc431069c3ac",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f86714cd-dc16-5e62-91a0-3038930cb29e",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d2e10a3-bb7b-55c2-beab-61410e0691ff",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3f2d0c1-530a-50b4-8025-b5c3c3f079f8",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a05daf17-266b-5b86-89fc-21fd32994110",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a43766a-34ac-5e8d-b9df-3ead1026d37b",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:172a253d-1916-5d21-87f0-9865d081c225",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4d6f87d-4216-513a-bc5e-9b78d599ecab",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.2 of org.springframework:spring-messaging. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0427fd69-3ecd-569b-8347-b8041537ced5",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07696588-d224-5a05-a8ff-4e4295168a75",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e28fb84-8715-5161-9806-1d6400a40db3",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13532578-59b3-51e6-90e9-1e5914ea215e",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a91fba19-948c-5954-9a09-9f44a87d30fd",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.2"
    }
  ]
}