{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3c4ece7b-8545-59be-b6a0-16ea02009bbc",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jdbc",
      "version": "5.3.27-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:12d02367-848e-5334-8df7-6c049f8d1e65",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49eb3898-d41f-5f87-aea6-e512c8440ddd",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44d07097-f35e-5210-a1ba-f8574cf019f4",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:415c5954-497d-53d8-9935-c8b01a61e8c1",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb6bb100-ae56-5f2e-bda7-0c9245273d4c",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4304c0f-0f05-5fff-8e9a-6554fbdd66f2",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c54bf8c9-fe89-5646-b22e-f6219a76a93b",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:186821b5-8775-539d-bb9e-96b0dac77add",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79a2814f-c785-5ab0-91ae-788e71cecdeb",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9dfdadd2-affa-5503-a766-f94838e2ef6f",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a106aa6-91e8-5810-8bf4-478b672adb95",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d7eb65d-b7cf-516f-baad-cd325c779133",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-jdbc 5.3.27-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a71f10ce-6566-5a76-8618-683511c9cf09",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b3b53fa-f6e9-5c7b-a7da-46334248e66b",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8643b314-2972-5d6b-891d-171c6aafa378",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7618b28-1565-5d52-b632-6f061210dcb8",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6be02bde-c903-5b1e-94e8-323aa096109b",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e41d708-fbcb-5a92-a89b-5d422669bc4d",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7afbeec3-41e1-5e4e-bcbe-0a46aabeccef",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ed32da0-8c1c-570b-a693-9d62f8fd9938",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f106e7ea-9a52-53dc-a4ee-55b423e91368",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7473cb4a-429b-5ecc-a3ac-0f215a890181",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0006063-db39-5ba7-a720-858757412aa6",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41840. The vulnerability was previously addressed through backport commits for CVE-2026-22740, which applied the identical doOnDiscard cleanup logic to prevent resource exhaustion from multipart request processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:428a3182-604e-5ea6-a597-62d2921877c9",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b391adb-4d37-582b-8e96-66ef610daf97",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9891d35-9d9b-5221-9018-067b19869f0a",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64598526-a274-5575-81d7-f4b9304813af",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ace820ef-5086-55a1-97db-84ed0d073376",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba83f179-aa4c-5d19-8132-6526031ac80a",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b842e88-6cf4-5e57-a9d8-615cdad2a2a4",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41847. The upstream commit 07ba95739bf4451742e4ee6b4d4b2d0ee5f701bf is present in the current branch, and source code inspection confirms the vulnerability has been patched."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76e78a19-e755-5ed3-ad73-b0fddde06b1d",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6c1af16-4e79-54d3-80f2-55e755324794",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13d02a87-9102-50b0-ba99-731abb63ae93",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ece860c-e813-5ce2-936a-1ba0244d5f4f",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86d4616d-1180-5dba-8520-c04194bd45df",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44b6c7cb-af51-5d64-8f1d-c8e8fc9486b5",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0acbd67-60f7-5c89-9b6f-e47aacdc83d9",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.27-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.27-tuxcare.3"
    }
  ]
}