{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:51aee10e-f0be-5e9e-9e16-aeae7ab6d682",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jms",
      "version": "5.3.27-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:afb11912-e460-5d51-8ab7-a9b2016a9213",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:581bf7bf-df69-56ac-847a-fc44b283f32a",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:272cee04-08e3-503e-9227-b7a6b889955b",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62059532-05c1-5e64-ae26-f0ec54de2980",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b979976-30a8-5b7c-91de-4d6d6f740a60",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5d1f984-491c-5b83-b9f9-c92123613f0f",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2533d91c-e933-5037-bc0a-5f961686410f",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:648a776b-04df-5a37-8ae9-e64620204f6b",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4c02e3c-b0d1-5376-bc7b-ce60b7936da3",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd9353cb-cefe-5861-976f-d5efc2c4b756",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91dfe157-9ce8-58e9-afed-7bb696abc0ff",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f0edd1b-1310-5eab-80b1-73c2b2c6add9",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-jms 5.3.27-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61341f63-d790-5b02-982e-6b5b8b9cb45c",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1eb58a3d-935d-5f09-938b-ff7522d00236",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24e66715-591b-558a-a5cc-a1b3ad44c018",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:545bbb13-b4fe-5398-a207-7e74c9bf53b3",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a548e699-ec32-5ad7-b064-293ffe8b7c23",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb5cd469-0995-51ff-ba64-2551e1b4537a",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38b85643-d9a3-55d9-bafe-5043962298ce",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56d4f1dc-d65e-504f-acba-99391364c985",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36c35af9-1f27-51f5-b207-bf0974c00e9e",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0e1c3cf-d3ff-5abc-8b51-29c76c56f5b6",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89bf61ee-211e-513f-b134-c4269a237a8b",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.27-tuxcare.2 of org.springframework:spring-jms. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41840. The vulnerability was previously addressed through backport commits for CVE-2026-22740, which applied the identical doOnDiscard cleanup logic to prevent resource exhaustion from multipart request processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd6fb19c-a8b3-50bb-ad15-514436716b7a",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a757f0f-cf71-5322-9f5a-291c134761be",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef8afafe-2d0b-52dc-a476-a642f0951bce",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd8ff991-f76a-558f-8ef1-26de6b79b30f",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23dce505-93be-5966-870d-78da66852c2f",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2605dffe-9a33-5a4b-a476-9af675b32986",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb6168bf-0a2d-5bdb-b92c-7795874cbb50",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.27-tuxcare.2 of org.springframework:spring-jms. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41847. The upstream commit 07ba95739bf4451742e4ee6b4d4b2d0ee5f701bf is present in the current branch, and source code inspection confirms the vulnerability has been patched."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8eb7657-3687-597b-b5d5-4613467c5120",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d5169ce-0a6c-5f3f-9783-77c789734f46",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a03cbe1-75a0-5fb5-8e0b-5b7caece79a6",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6622d8f1-b1d7-5a9b-af4f-505ec8d26aee",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:920c9258-de68-5108-b035-859bf2cc3c6f",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f70f2a2-2937-54cb-8941-84322aa2c70b",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8f1dfd7-b1dc-5bd2-9be9-772cc86e6466",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.27-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jms@5.3.27-tuxcare.2"
    }
  ]
}