{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5b3cf1be-79cb-5dcf-a09d-c84693e7728b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-messaging",
      "version": "5.3.27-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6674cefc-770d-56f1-a00e-8cdaca1a2673",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55935d8b-ed6d-53e8-8296-cfa4a94385d1",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc722ee1-a7a3-5ea2-bf7f-f2b9e8b3f84b",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0937e488-aa61-5cff-9c11-31e593a51a9b",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c51ffe0-753b-5faa-b61a-77be2e9c56da",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:471c1740-c74b-5193-b8a9-a7d9edd77aab",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b0fea40-8121-56d1-a8ec-8c3494a990c7",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a41e01b-b906-52ac-b9d2-d254693761f4",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d651649-0a11-59de-8f64-7e7d38fb661d",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:423a5727-0597-5fcb-be08-ef2d4a83f82a",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:812e91d9-a88e-58a8-8513-a6d2793e26ba",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebe616ff-39e8-534d-b008-9bad854cabc8",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-messaging 5.3.27-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cab9db79-ff7e-5ec0-9e5b-26542df44062",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1a75f39-b54d-5954-9390-ff59f51de5a3",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41010113-5abd-5774-9071-c3de0ff49d82",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a39ad132-1767-5fdb-a498-c3cf591f09b1",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77377092-58d4-5654-8381-430ed30fe7e3",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c2981e0-9f6e-5ec9-8876-873a14bae66c",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0e06050-f0f5-5e8c-8b37-8871151c91c9",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ac32a36-b83d-56ed-82d5-a84e644c343a",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:655ee494-2fb4-5fd7-ae77-4a241aaebbfb",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abf59fb0-727c-5fe5-9825-5310116e5ce8",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:516146a0-d46a-5096-b85b-24f6feb1169a",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.27-tuxcare.3 of org.springframework:spring-messaging. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41840. The vulnerability was previously addressed through backport commits for CVE-2026-22740, which applied the identical doOnDiscard cleanup logic to prevent resource exhaustion from multipart request processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9fe7c6e-4e1e-53fc-954e-4fd221bd5c65",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e849ff3b-244c-5c04-b574-7ab271c9e50a",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52e7116e-e502-5f48-aa9a-b332c06f9a96",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31df6206-e4c0-5164-97a7-d9e1dad9e4b4",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c079d551-52f6-5116-8baa-f5394090a511",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82db1fa9-4e3e-51d0-9978-787e178c814e",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdbae8f5-d58a-5f2c-b47e-7e757df5f0d8",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.27-tuxcare.3 of org.springframework:spring-messaging. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41847. The upstream commit 07ba95739bf4451742e4ee6b4d4b2d0ee5f701bf is present in the current branch, and source code inspection confirms the vulnerability has been patched."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7854644-4452-51ff-83c0-4ae1156955a4",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff604624-6512-55e0-bb69-f7fd5cfcc1d5",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d57c7dae-842e-5fbb-a051-50afc8d4b5d9",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fab4bf0d-793b-5eda-b2c7-e15e98789b53",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:688e0c16-8177-512a-bb7a-556b30a3f6b6",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd698367-a504-5598-8542-d27f4e621af6",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42e95893-a18b-5287-a75a-4a6654576786",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.27-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-messaging@5.3.27-tuxcare.3"
    }
  ]
}