{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:67b93a71-a637-5d1c-a661-938ac3b2f7be",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-tx",
      "version": "5.3.29-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:cc57d100-084a-5c6d-a8d4-e9118c316e79",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fea90a2-aa88-5040-9e16-db14d0a8492e",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e512922b-3387-53c2-87b2-961232b3a856",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1d66172-e98a-5714-90ec-71af725c10af",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bf27628-8ab7-5592-8b15-ec3e352b2238",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:306fb4b9-fab0-5494-9500-5515db759e73",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0663b8ac-0117-5665-85a9-67e3c815cee1",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a95301f-23b8-5292-945b-e069ddfe94d2",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fac052f-1f3e-5802-901d-f0fafc052336",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ae4d843-2ab9-5a98-9cb3-fac7e9b76aa9",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:073ba9b5-e678-59ea-9125-e910228b3b08",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bacacd8-35f2-5922-af0b-9c3150285683",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-tx 5.3.29-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64a8e493-26fa-51c5-ac95-d506d61e1565",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ae6c10c-616a-595e-8091-40a051a9e652",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccd92830-9e2e-5141-9e93-a8a462dce5e0",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f90f68a-8d6e-562a-8659-aca0836b7b73",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65c2f452-a479-5360-bcc8-cbcc9333ee5c",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22443863-76c3-524a-bb18-b931b993f007",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb231303-0175-5f0a-9d65-42d170d841ae",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c807905-f877-5a78-bf60-0503cd1c04ee",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4b927a8-b065-51e4-8614-cfdd6e2dc3bf",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b072e961-a674-568c-b152-d0eb68ea53e2",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcf20be5-de51-5c3a-8b81-4377ab8b3718",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.29-tuxcare.5 of org.springframework:spring-tx. already_fixed \u2014 The target repository (Spring Framework 5.3.29-tuxcare.4) already contains the complete fix for CVE-2026-41840. The fix was applied on 2026-05-19 as part of a TuxCare backport for CVE-2026-22740 (commit bc0026ae70c), which addresses the same multipart request DoS vulnerability with identical code changes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ea30419-ef6f-571f-8298-8be084eb5417",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fccb97c-da17-5319-aa59-06820cdcdee2",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28fe9e8e-83e3-5564-807b-cebd54e4cfa3",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f3c9f86-7cc3-514c-b897-e83b7759ecae",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebb5f890-b31b-50d6-bbd6-0d14efc02d17",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ad1eb2a-6720-5178-8b33-e27f321aa0e4",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:935189ac-0f76-5db7-be6b-ae6bf8fd2f6a",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d307e49-72bc-5d4f-93fa-e6d1af37a134",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bc4e11c-7363-5106-bb06-0b4441418141",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:185edc27-c20f-500b-80d8-9bc813de57a6",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:319aee5c-4ed5-5fcb-81dd-b6c99139cdca",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:417304cb-05fb-5ba2-a5a5-ea7b975e7f4a",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04a09e02-4b83-5fcc-8c20-75d4b63b36ce",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:458cbf42-a707-5955-9ee7-c9af99fa581c",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.29-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-tx@5.3.29-tuxcare.5"
    }
  ]
}