{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5a984c5f-cc9a-59ab-a68c-55b35756a32a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-messaging",
      "version": "5.3.27-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f42c4b7e-f7bc-56d6-a437-1b32a40fd8d9",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79fb549b-b675-576a-8004-66b27d21dc36",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c07f411f-63a0-58cb-a189-6092c64f33d1",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de356ab2-6b01-591c-9ed3-7e8834fbf727",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bdc3ac0-436b-5943-9d63-e07b6b6f0e56",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:319aec0a-9329-5ba6-89bb-03afc07227f0",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a93dc80d-8dba-5e68-9869-904b1644cb8b",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b235875-53c7-58cf-b994-cd8d5b940b23",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96a9bf65-bae8-5f69-925b-3ab492fb4ea4",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b832968c-2235-50e5-a48a-230a7a1b112f",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f186a905-f858-5fa4-b338-d002d126cb99",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:200dd7e9-155b-5e0a-ad8c-4dea9464c790",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-messaging 5.3.27-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff48e5f5-cafd-507c-bf89-b7cc085485bb",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4d3e62f-5017-5200-ba5b-ecf1940cf828",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6374f8f8-5fcb-5e13-bfe4-a25c28537e69",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:553fd02d-710a-589d-a4cf-7537c8f75a76",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ff6c6c1-a24e-5706-84ba-a63db3560cb6",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32848fab-978b-541d-a2b4-3c2521e966bd",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3feda38f-3f00-5448-9eca-ff008205b397",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc1352b3-89c3-5b70-a37e-b10fb7916d0c",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8162c470-6c90-5fef-9117-4451c80c9bf9",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c0d4bff-5005-5ea0-af80-76569c75230f",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e32cb800-c3d3-598d-b14c-7b74778e547f",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.27-tuxcare.2 of org.springframework:spring-messaging. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41840. The vulnerability was previously addressed through backport commits for CVE-2026-22740, which applied the identical doOnDiscard cleanup logic to prevent resource exhaustion from multipart request processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:710fbfe5-3e68-5ec2-bec3-2f0db5fb0e13",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e5efd5d-d576-5604-8453-6f1492787d7f",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62bcd9a4-ec67-5577-92e6-fae10cbed104",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9ed9368-7623-5e90-8c09-5096d883e70e",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee7a227f-c74a-5174-b253-a4369d99b63d",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7d59139-a127-5fd9-9ad4-912b27ab6186",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78f67367-df45-58eb-a14c-27db7c33ac1f",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.27-tuxcare.2 of org.springframework:spring-messaging. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41847. The upstream commit 07ba95739bf4451742e4ee6b4d4b2d0ee5f701bf is present in the current branch, and source code inspection confirms the vulnerability has been patched."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afe28f0a-ed0a-56e9-b937-351fd43940f5",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b035420-9779-5ba0-90aa-0d3ae839b0dc",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4e4b6c5-d7c7-52b3-b527-1847c731f80f",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5159cf9-2a48-563b-b92f-9135087b213b",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:921da00b-db87-5bb0-a3d4-e59c8e67db40",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00769bf4-4f4b-549b-b11c-7ced935fabee",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e62d5da1-9a42-5edf-b690-043684acc56e",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.27-tuxcare.2 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.2"
    }
  ]
}