{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b6220277-0f0f-51e9-bac7-03dd2eb8bf47",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jms",
      "version": "5.3.31-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:083b03d6-9d20-5bd1-9d71-b5c6cd299d07",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:429b946b-99ac-51e1-ba24-a0566b373ae6",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3206530f-64fa-5aff-b25a-666f0db73156",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b6e2670-d1c5-5d4b-ab78-eb36f98d97d8",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c45b7c36-062c-5351-9d40-f362c842354e",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0c5a91d-9bc0-589e-8de1-f318a9e83d3d",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a558563a-d729-5005-a9df-db91ef132d8f",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59e057cf-8046-580f-9224-c4234994a075",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:841519b2-c13f-590a-8379-7396059a9035",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a031a697-9815-5322-b87b-4d41f0ca0fe6",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93cbae44-f62f-587c-8008-e37054752725",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d130ad1-e391-5410-ac7a-0edb419a79be",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-jms 5.3.31-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf70fe18-8442-5510-b2bc-c810544dfb68",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:024e1542-ec6f-59e8-a306-c971f5f1843d",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0f04277-dcb1-51e9-8c2b-8e735ab68d22",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:456ed770-8346-5d17-94e0-48feb5ed76fa",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:615afb8a-17b2-5312-891e-e755c283f6d6",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bfc18d6-39d4-549f-8e32-3fe675f1b066",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f411338-fd65-5d30-9d74-61b81df21930",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53b42d04-9a8c-5d27-807b-72210b32a2d3",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40820a84-eac7-5cec-9272-08ae9f4e875b",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8254c283-81a1-5bea-b4ea-8b1e8f2db574",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ac09d29-a16d-5fde-be04-725125af0903",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.2 of org.springframework:spring-jms. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d73f71d-29ee-590f-89fb-dffcd5fb3cdf",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5dce8bab-9a83-5c5c-87f0-85b906b117ae",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86e03954-214e-5f4c-8179-7aa69da67aef",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f78a103-5027-5803-8b95-679bd1c8f6a4",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e4f711d-0843-5bc0-9dd2-7f0ec7308385",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63d98bb7-cfd9-5a01-9e44-2001e946f4d2",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0aaf18a5-df42-544a-b23b-221b87d0c8bf",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fe02e49-2cda-59ac-b717-4541ec0c3780",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03b057b8-39b8-5b7b-b94e-0b120b6b36af",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d5b59e0-276e-532c-bc97-e3d3059e3b24",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce77cb30-db01-595c-b413-ae54d5f1a208",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:186c87f4-1f75-5c96-9af8-1e677296934b",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d7785ec-2bce-51cd-9322-31fe1d25cd86",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84f88fa8-52df-5d47-b189-7b0e0840b21a",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.31-tuxcare.2 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jms@5.3.31-tuxcare.2"
    }
  ]
}