{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ad9438c1-317b-55a7-b013-b935bd632e01",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-orm",
      "version": "5.3.37-tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e5e7aea2-13bd-55d9-9a0f-45dce0a5ccf6",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:931d8bac-30b2-5f9d-8c79-ae8db26b9f03",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43de524b-aab6-5770-87ef-fe01deeb2964",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3190c1b4-4bbc-5ffa-a541-7862c1225ff9",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38816 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46899a5d-28cf-5d63-9c9d-b3bd91017389",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:919488b4-c994-5743-a294-e188e75ba346",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18a08ae0-8f0e-5f50-8d6f-ddaae33a2849",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e657b0ba-978c-5c27-ae37-82d3438ca025",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38c3ceb7-7b6e-5b86-b39d-826d94c19500",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:971e2269-16d9-5d1b-8dc3-ab31bc5ebcf3",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2f20b42-a10d-5099-a03d-e35b000fc933",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46b84df0-2751-5ec0-bc77-b8a0ead54f4b",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb6c360c-8e11-5d4a-a268-67e3872bb3be",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fcf0bc8-18f0-5ff4-8efa-6657cebc8432",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6e43174-a45d-5dd0-a9de-6ba671141be4",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ea33ae9-e5ab-58d2-8d44-260365299c97",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78a33570-9a11-5168-aefe-a70a1e32316a",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3785e1d3-db2c-5a87-8e30-fee73581392d",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d968365-ebd8-532b-be3f-85c0ffa5ecdf",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.1 of org.springframework:spring-orm. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84408bbe-815d-5408-a328-779c13c0fcf2",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a7391c9-0836-5b59-a186-a6c8462ca731",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8cd253f-31b7-573c-b576-6b4b9a233936",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a9137f3-3845-52d1-8b65-bae5d3137b6f",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73f2ce32-a6f3-5399-bdd3-aa060902808e",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7097a8bd-eeb3-56d9-bd1d-6bbc4ac63b2c",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b07ce231-71b2-5b10-90fe-f081c5fb2e6f",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27f376be-fa53-5ebb-94de-933d619ac42d",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e983416f-c05b-5611-bbd4-ed6e69f3e52d",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.1 of org.springframework:spring-orm. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47f26b32-ab43-584e-b89d-1c9f7fd4af00",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fd6ab0a-a9fe-51e9-a95b-6d32cd686deb",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:456d63a6-e107-5208-b713-41073a750323",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9e8142d-b42c-56fc-a057-a5474e1dc167",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec48576f-6e45-57bb-91fc-532542b2f36e",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-orm@5.3.37-tuxcare.1"
    }
  ]
}