{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2bc71d27-11c5-5cf8-8c62-0a793e5a88dd",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jcl",
      "version": "5.2.13.RELEASE-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:534931c5-f4f2-5d95-861a-95ac4653f15b",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce243aed-8742-5abc-a777-59f1de71eead",
      "id": "CVE-2021-22060",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22060 is fixed in version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe6decad-5117-55e8-b95c-069ccf536d0c",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcd57de0-d5b5-5f61-b400-cb8d1dcc0c03",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d39e38f1-53df-5dc0-bdc0-eab07fc64ccc",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:893cb35e-b9cf-5bdf-a6f6-dffeba2f5f53",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36289969-6c3c-5aa9-a8d5-bd244b73d93c",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01321071-0b34-5ef2-af5d-7ea3febea0ef",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1dc380d-5fcd-51ea-99eb-739e82949238",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:401ca219-1500-51bd-9ab9-fb01444076f0",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc83faa5-2745-5404-9689-fe9ab68d5912",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fffe6516-92d3-53bc-812c-bfb13764f8cf",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb4ed6c7-cadb-57ac-838a-35e80137a6c1",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f7dc718-c721-5947-bb3e-e1a2973c3a81",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30b733c7-b0c8-5a97-a2f7-e37ae7b84e87",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:504e53e1-3ba7-5850-9a9b-31e346c5c032",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:560d0829-bd1b-506b-86d9-eac0613b56c5",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfc9b259-395a-5cc3-9b58-2bc0796951de",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:895ef9ab-2bc2-58df-a32f-2e4fba1c0b65",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d8d2028-8df0-5104-9606-da3708f72015",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41a33d41-8545-5ba0-b234-6b02bc7e7fb8",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41234 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1e5fff7-7e98-53b9-9b48-c85964f07ff7",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05df0be8-76b4-5fcc-97f7-acefc34acb74",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8eb5c10-c6e6-5f49-8270-363b729ca4e0",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a81a5fc-1a47-5753-b8fb-c368d26c812d",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aaa4c3c0-fe94-5122-a985-b028a552e40f",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bb62f5b-f66c-53bb-bb58-6891a9d5c93c",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4e045ce-bbcf-5493-8ecb-8360586576c4",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ace504e3-f132-577e-8b03-6747bbe0f8dd",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl. not_affected \u2014 Version 5.2.13.RELEASE uses a fundamentally different multipart parsing architecture (Synchronoss NIO library) that does not contain the vulnerable components targeted by CVE-2026-41840. The CVE explicitly lists affected versions starting at 5.3.0+, and the patches fix issues in PartGenerator and MultipartParser classes that do not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e4a52ef-8c06-502a-b003-4b7e43f772a1",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05c7c4ed-a1d1-5c83-a1e0-f9a76583e92f",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:599e86ed-e085-5bbb-992e-bc2d41b20885",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80227206-e2b4-5bf7-a33e-36db66c98374",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f655800e-2af1-5f04-85d2-9a9dbeb1072a",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8b799d8-3531-5e44-9a3c-e599ee2482f2",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c264971-6b80-58f4-bcac-5ec84997e82e",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da9ef518-5fd5-5f28-81fd-39b70bc015d6",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39735803-6374-50a4-8b3a-f71c2fe624ca",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99f671e6-2bae-512d-991c-ad0195786fb1",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac2e80b6-95c0-531e-ac5d-8b2b48fe79f2",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59083dd7-137a-59ea-903a-543946a7296c",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:652cacbf-5e6c-5f3b-af10-914586e997bb",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12c02b27-687b-54ae-b5fe-4af8525e7c55",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.2.13.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jcl@5.2.13.RELEASE-tuxcare.4"
    }
  ]
}