{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:76d29528-1fa9-5fb5-a9ef-8234bcd5d28f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-messaging",
      "version": "5.3.29-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e34dd21a-f375-5f5f-983d-a682cca5359a",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0d667d3-e5e0-5f28-9ab4-7f91650fab2a",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a65905b9-a508-5f18-ab0b-ef2da6262598",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4d599a5-dcbf-51db-837c-7a4971b58398",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21759165-b9d4-540a-bfca-978203b39921",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b316f7cd-fda2-5e24-8bcd-2c9810b5c562",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb2f4140-b16d-5e71-884e-70d3011d3761",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e73a267-2e01-5fd8-b77d-9cb88c16053d",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c743a1c0-aecb-5b2d-baf5-e8c10fcb7fa3",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:169fba13-777b-5904-bf8c-4be259b4498b",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a69d6ab4-cdf7-5456-9283-3e697eaac91a",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a52cf589-1674-54ac-8ae9-5415c61cc90f",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-messaging 5.3.29-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09c4419f-c7c2-5b9e-a003-107cca1bc740",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb777db0-368a-50a6-97fd-afd66c8793d5",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fad4215b-99fd-5820-b74a-d088c344a116",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e86b1cb0-5af5-5ab9-aee6-ea1055869aca",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9a203b8-15e8-590e-b345-f17cbae3113a",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c8b2865-0d4e-5c5c-a635-5ae1102765d8",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:476a308e-8136-57df-bee0-ee74e4c772d3",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d34f05cd-bac2-567b-9720-2416e101d0a6",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7468a7fd-7c87-504d-87e1-d0a6a70847af",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:150338c9-3637-51e2-9f9b-acc231b1d19d",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38eeda08-e1df-5cb6-82b3-1ebc491c144d",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.29-tuxcare.3 of org.springframework:spring-messaging. already_fixed \u2014 The target repository (Spring Framework 5.3.29-tuxcare.4) already contains the complete fix for CVE-2026-41840. The fix was applied on 2026-05-19 as part of a TuxCare backport for CVE-2026-22740 (commit bc0026ae70c), which addresses the same multipart request DoS vulnerability with identical code changes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e691ef18-5ce9-5a81-ab90-5b6120935f13",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10448940-e515-5b59-aa7d-66a667496d93",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4418f421-2094-59a7-af04-2be1e7f056b8",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09806890-4492-547f-acc3-e2cc37f49bcf",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:739d2e6c-b20d-5361-aecb-e024cf210ed9",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b82a8eea-0ab3-5ec2-a874-cfc6c5afc9f7",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b74dc3a7-29e3-5e4f-a94e-ae3e7d492994",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5a13522-5f2c-596a-82ce-638796250a04",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e03d62e6-1989-569c-b3eb-4190f22af954",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0361186d-332a-5a5e-897b-31142b2b7c67",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa960bd7-9341-5d65-9624-44679096d45a",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1c9fbc3-48d1-5b79-9d29-60a84977a9fc",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46842c47-e9b8-519a-8845-45dd680baed8",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29c03d34-8649-542a-91a9-82aa5efa70a4",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.29-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-messaging@5.3.29-tuxcare.3"
    }
  ]
}