{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c3480400-8c70-58b9-a8a7-04c75266362c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-tx",
      "version": "5.3.39-tuxcare.17",
      "purl": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5cd74fa3-0038-5ab6-a5ae-a9215a33013e",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:060d9bfc-08bd-5c4d-b5f5-67e26120278d",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.17 of org.springframework:spring-tx. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0384f14-2e6b-5d77-b562-76c2ed4967a9",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:919b31f9-3898-5290-b917-1d35dd611bf3",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d0ac196-2d13-5e4b-8e42-f670bf0b2e62",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed3d1af4-e7e6-53ee-a0c5-f35d44a4b061",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e0cfe70-2614-5710-a8ec-5528b8a12426",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:422a8806-0b9f-569e-b79b-62888ca0eac2",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-tx 5.3.39-tuxcare.17."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07b2e89d-f292-58df-95d4-6312dd9967bb",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34486755-84b5-5eb1-abfa-e24fbf04190a",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ffdc06f-8476-52de-b3b5-a5d30ce3c54c",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:326fec56-f2c0-51da-8320-b6d8afe9dba1",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85d065bd-30de-5ae6-b59e-88571a57ab0e",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6265bcc-5d27-536f-b44d-6ab17eba9ede",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fdd2ded-7e38-5364-8fe5-8d9b1668dfcd",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:888c8e3c-ddd7-529e-840d-4f42486b1fa0",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c437693-fad7-54aa-b69d-4bdcfcd36fce",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7551251f-91c4-5f63-975d-1edc9d1dae35",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c9e64c2-3bcd-507e-a666-4e931d730acb",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.17 of org.springframework:spring-tx. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2ddb03d-02ec-5424-9e42-bc06b5347f20",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b44f4447-a1ea-5714-9bba-1b78c7e659c8",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2570288-d091-53d6-902d-a5b989e9b27d",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dedaed73-42c8-53f6-a989-c53c113decd5",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5a73bca-eb97-5bee-8005-b59a021203e1",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b06cbdba-05dc-543d-9bf5-b6a9bd35449a",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:477ba39a-56f7-5d6a-961e-ae69876d1bd0",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1f01c0a-0385-51c5-a46b-4e62c4b8dd3d",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dea02351-95c3-506a-abd0-97fe69aae2aa",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bb0ceea-1e53-542e-8ee0-fd063bcc180f",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f93ce5ba-05f2-5bbe-a8fd-1de89cb772f0",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2ddf0b8-53f0-54c0-9058-9cac57586490",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2862789-81c1-5c21-b522-8703d5a01c82",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:869353c8-f9d2-5af2-8465-177b7c940052",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.17"
    }
  ]
}