{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:85e1a42b-ad78-55b3-90d6-6b5a923c787b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jdbc",
      "version": "5.3.39-tuxcare.11",
      "purl": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:3414528b-1d48-5d94-98f0-5042118d89e0",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:950cecf7-99c8-51c5-99f5-bbc8cac05f41",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7d72358-ca9d-51b0-83ee-a97ecb3b73b8",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d256f1f5-b7b9-5cbb-8a5f-f7872c29b5dc",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc040aa0-f815-5039-9491-9359328eddd1",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9d04cd5-e276-5f83-8e3f-2c0071b3a3c5",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3ead034-db8c-5c60-b095-ee84eea4e5d0",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8917ddd5-2596-53c4-a164-f9c285a4683c",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-jdbc 5.3.39-tuxcare.11."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a485b4b-4570-52b8-82fd-83161a724e58",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00ab27ad-b8be-5c20-a2e8-10e13a997a3c",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9edf8be-c41e-57f6-b2bc-841a746d613b",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fcad2fc-4cab-58eb-859d-5fc9fc748478",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f9faa77-65ce-59ad-ba37-eb2d0bab6a50",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7580f14f-fe96-577c-971b-b635af79c823",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fedb4ce-34e6-56ba-a46f-8ca7d3ba250c",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18634371-6407-5c44-ab40-bfb6f07947df",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40582bd1-ce3a-5158-a920-fbb5d8059b23",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:142a56fc-cb28-5879-a6b4-ca3ea59a2d8e",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adbf8645-08c7-5593-890a-4259046b25ab",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:876fba21-7104-5dc2-aa16-84d5c319ed23",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a138c9f1-d73a-5b37-ae1d-aaef17f10532",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b7650b3-f13b-5cf3-a17a-4bc5c2fb6ffe",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e95cda16-c3c8-5b68-acf0-692708c48c1b",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d775ad21-1c08-508e-adba-ef70d470617e",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:964596ad-9dd2-56de-9248-8b9e5e9ab811",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b688dcb4-1ed8-51e4-8e4b-f41cf4f745b3",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbe6751f-7af1-5603-a783-f1babfbb52a1",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81ecd9ac-5c26-535c-9265-7c15c9d905e9",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d700499-19a6-53d4-8be5-8395a85e6a79",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c092e161-a6f7-51ea-84f8-112db8d805fd",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42fc7325-59bc-5670-80ca-090bca508f24",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb2e263e-7aad-551a-943b-ad7e1d87dd59",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13c442f5-bf68-546f-96aa-a44f366093e7",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.11 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.39-tuxcare.11"
    }
  ]
}