{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6b7377cf-f8e3-5fd6-ad2c-cc8fc9eeccb0",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jdbc",
      "version": "5.3.29-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b7975e98-902d-5612-97bd-9e231a4d4167",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2eddce70-24cd-508c-9716-afe2892e3f8a",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2427dd40-0653-590d-81a8-52d15180accd",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bdf944a-5879-57ed-8ecd-a59b15e3784e",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccc5255b-9c29-566c-9423-06beef25f126",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a985d30-cc55-5892-baf4-ea218c2b318c",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d5b9b51-d60a-55ea-9226-12dd2a929cf6",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd7a2fef-c8fe-5f69-8634-414a1dd24756",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39b9bcb9-dd66-5ddb-8a85-e48e33548087",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24c38035-0b80-52cd-a85a-50f7a94c4cd1",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8cf33a4-febe-50c0-9db8-249320c4bc2d",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:606a905d-60c3-524f-bcd9-2aa5948dd511",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-jdbc 5.3.29-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc35ba5d-efc0-50ce-901d-59186cad2cbd",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04ac6dae-5c1c-5cd4-a84d-93e902f93a45",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09afb28c-afe5-5c1f-ada2-05a6c9c9cf7f",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3642e7f-054f-58ee-90a4-ff3fa9f0bddb",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61d8fed2-0e27-5b97-9c3c-b92e1a78cd46",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f55eb134-8fd4-51fa-82e3-8b4b6be687a5",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:461e9bd8-b1a5-5666-9037-b9ad9438097e",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f335890-6b79-54a7-b101-0b13aeef9af7",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:974eec54-bb43-51c4-bfa3-1b2543d2f807",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7dfbef3-ac3a-5376-a571-37369f230717",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e831e49e-4ec5-5e43-8861-6882b1156fcc",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc. already_fixed \u2014 The target repository (Spring Framework 5.3.29-tuxcare.4) already contains the complete fix for CVE-2026-41840. The fix was applied on 2026-05-19 as part of a TuxCare backport for CVE-2026-22740 (commit bc0026ae70c), which addresses the same multipart request DoS vulnerability with identical code changes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:536d64cf-88cc-5c21-9caa-5001441be760",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7742197-9e7b-5f12-bff6-01c1ecf918fb",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37e7e576-cc8f-5740-98ea-4fde037df4f0",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c18027dd-edfe-50c6-ba7c-d66f32f75c52",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6ec4b40-9b85-5cdc-80fb-5d56f0498f16",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8035eed9-acaa-53cb-8365-c1b2f12dbae3",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d963f48-76a4-587c-8ee2-b8029c076e4e",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e891ec6b-9c22-5714-a422-b20a51f4a261",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34ba75f4-bc1c-5c98-afd1-f9977e41e2be",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b01612fe-02cb-5ecf-90ac-0879dca2afce",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9f6c61b-247d-503d-b1c4-5f9a0e61e3db",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c8f9fd8-12c7-5c70-8d53-a6ac83db4d50",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5e863c3-277f-59a5-95e7-7e6e5f9295fa",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:200ff4d1-945c-59e3-bc15-741e397aa0e4",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.29-tuxcare.3 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.3"
    }
  ]
}