{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0f4dcb1c-cca4-5123-9e4b-6df467c8ed52",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jdbc",
      "version": "5.3.29-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:059edd45-825d-578e-9613-f13ce17d32b7",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6aaa56a9-435c-5e81-a44b-18c2de153a75",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d12e0f9-56cd-50f7-b168-4b24e49adc54",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ea68a64-0f79-5a3b-9482-95b77b62b19f",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a16e72d8-555d-54fa-8dd2-fa067b95be2b",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c23f7ebd-aa71-5a0f-8e5a-2d7ee6377761",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33a74554-424f-593e-bdce-c5f8e67ee3a6",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58434e77-65c7-589d-9dd3-bd80125c3c78",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9be82d2d-0ee2-5b41-abd6-e86575de28e5",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d168150e-d20d-5dd8-853a-8676c22b1a61",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:568b6e7d-1141-569c-b108-486779b6e048",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9973ae91-c90a-5369-8ab8-92ba37086f69",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-jdbc 5.3.29-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e203159b-5191-560e-bdce-9a53a740acd8",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0edf7316-6e26-5a3e-8804-b440c4083215",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81ca1b71-5f28-591c-936f-8d922002f0db",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49c746d8-67a3-5b84-ad12-cef0533aa7d2",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7f3de05-537d-5561-bfb8-d07aa7b9b0de",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7ffabcf-5fc1-5c2b-b625-35d0737be9ec",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3fc4545-d9ab-5c6a-bd07-99c69ef88ed4",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c99b40e-b0f5-5784-b151-619186da528f",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9109a53-8313-57c6-b5e0-47ee92809d44",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:752a42df-48c0-568b-865a-92cdd76423c0",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1606c082-3bdd-5799-bf0f-63381decd8d7",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc. already_fixed \u2014 The target repository (Spring Framework 5.3.29-tuxcare.4) already contains the complete fix for CVE-2026-41840. The fix was applied on 2026-05-19 as part of a TuxCare backport for CVE-2026-22740 (commit bc0026ae70c), which addresses the same multipart request DoS vulnerability with identical code changes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:398e622c-5aa8-5223-ac66-9bff64827383",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66879dbf-9ad0-56a0-8959-66ae6d996be6",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36aad539-a557-548d-80b7-690d23969fc1",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e4c19d9-15a2-514b-9867-f37a518e962a",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e045417c-8bf8-5080-b311-ae13f01f2316",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c8aa016-b230-5a22-9aea-769471111f2e",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5596a23-6972-597d-b3f7-a6aafa9dee1f",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a4adbd4-809a-57ee-b58c-9fed4c2392ac",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0eb56bf-4ab6-5911-b1bc-c43a9065b9af",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f40f29f-ca5b-59b3-bf44-1ac7806a0d53",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98d0cfde-edd8-5d6a-b783-b732b26e8390",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be555242-c224-5c52-bad7-f85c3d08f4c4",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f305b8b-44c3-51dd-bc2f-06d70bdb87dd",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9bec812-baba-5666-9b95-6eb255c0b163",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.29-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.29-tuxcare.4"
    }
  ]
}