{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:94f339dd-b97f-5224-a8b1-fe27a3a0f2b0",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-aspects",
      "version": "5.3.27.tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5a2f13b4-c397-5ea3-a901-a85d29f43ad1",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:599217cb-3afc-53e0-b893-cefdc4adfff3",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d087a9ca-dd94-546c-bcf4-5032197263af",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:060fc914-ec94-53d7-871a-a56bdc4bb5d7",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d89314e8-7275-51f2-8d79-cf65aa3a29d9",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46754e90-f469-50c9-be65-0ce1a86bd559",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7e623e8-31e7-55d2-bd36-b9d622e6995b",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38816 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59122609-1e2f-548b-b918-10ba49eb57c9",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a952477f-284e-5e3d-bb7b-1aaf298518a5",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b129fffe-00a5-5fd3-9529-c96704ba8803",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:852f5b8f-9cf8-55c0-9db0-5e86d61e7441",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:831a0aab-3cdf-5f85-9c37-5c38b86941e2",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-aspects 5.3.27.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:244d4ddd-340e-5c58-a181-334ff78d4f40",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9418b26-fdd7-57aa-82c8-ca07bd7c037b",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e8c4b71-6bea-5b0c-b808-8a39dbe347ea",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc054c3d-67c9-5d8a-98c1-80779dc0b357",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71ca8ad6-7798-5e3c-a268-80693987ebb1",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b012cde-101a-50e2-92be-620f68a528b2",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a28ccae-c14c-5d9a-bd01-b0f11302a110",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de2d9f52-ce01-5bb3-879c-1f339ac1e1dd",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7769b3bf-d25f-5251-8aae-b59d741014cd",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bbbbe7e-b520-53eb-b54a-ca408ded1910",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6587dfab-8b70-59a0-8561-dae73bf9e8b1",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.27.tuxcare.1 of org.springframework:spring-aspects. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41840. The vulnerability was previously addressed through backport commits for CVE-2026-22740, which applied the identical doOnDiscard cleanup logic to prevent resource exhaustion from multipart request processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46048630-d493-5329-927d-affe61ec07dc",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:265824de-a314-5154-9069-2120323dc812",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b54f2a6a-ab42-59a5-8940-9f83917b165d",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5956397-6404-5b36-bf69-8bf18644192d",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fecc563-6396-5494-94f5-ad4456450ccf",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d13b4172-eca9-5897-b92d-98939a5d65f3",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a17de65e-a57d-5e40-97b0-5a1fe99dfdac",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.27.tuxcare.1 of org.springframework:spring-aspects. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41847. The upstream commit 07ba95739bf4451742e4ee6b4d4b2d0ee5f701bf is present in the current branch, and source code inspection confirms the vulnerability has been patched."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:859b9dd7-a359-5ebe-971b-d05a3438a186",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f28e76ca-8342-540a-a5d3-37aa64748112",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f697946-786f-5c2d-9827-50e1e5ec8fd5",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:987e42bf-7af2-5deb-84f7-fc1765a32616",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15c33610-a7e6-50dc-893f-f7f8a8b24ed9",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ad93185-7ded-5326-a7d8-f1127f8d97a4",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e767b89-a7ed-55e6-ab5e-b9538c14c580",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.27.tuxcare.1 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27.tuxcare.1"
    }
  ]
}