{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:783aab6a-cd32-5016-8805-886c82acc5e3",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-messaging",
      "version": "5.3.39.tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0f911b89-16da-5160-8b52-471dbb96a6dc",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5664b32a-4d1d-5488-95ef-fb4cb256819f",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39.tuxcare.3 of org.springframework:spring-messaging. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97026e56-db6d-56b3-9abc-d43ebafbf279",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85d53dba-e912-57ea-88da-72923d159946",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14a0f8c9-596c-5b3a-97ef-957e3d048010",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a026a156-6b07-5c48-815e-e24938aab9d6",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f76d38a6-af9b-5203-9dcd-20ce935f92fc",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b7d6f54-9836-5093-a927-5a36f7231984",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-messaging 5.3.39.tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:117d251c-f5ca-577e-9868-fe66d515e871",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:726d84e0-f30a-5bfc-a7aa-3e6ef92eb45c",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:337ae443-828a-5654-9dd5-f85f4042fae3",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9617a3b5-7e60-5aa9-8dc4-c5d8e3f7ae0e",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:393fbcbf-c465-504f-899e-4acc5635b703",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:208695b2-a9a3-5b07-a2af-2bcf04c4b838",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70eaca28-1686-5150-ae40-c0b0dafdab11",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb60d48d-e978-515b-9de1-519c735d0908",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf311dcd-dd28-56de-bb94-4051fcc42f7e",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e832df12-5e87-514d-bd85-fc98cb38dcfb",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75e3302e-e9ef-5f18-93ea-07dc8f432a52",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39.tuxcare.3 of org.springframework:spring-messaging. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e5619dd-ff4a-5bbc-9560-b4174d2824aa",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8880ab4c-7d5c-5d2a-b05f-527bef6c4094",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16170ff5-992e-549d-b178-e48ff77a7a50",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bec461e-9e80-567d-b3fd-368382b45eed",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd21b6ed-028e-58da-9983-fa042e5cfc25",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:973db117-7ac5-578d-835d-6c37a1b3c7ab",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:697d5163-f9b1-5485-9d76-ddbbe5590c3a",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:566d044f-a0a8-5da1-be17-c2bfa269dcc6",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70676ef1-873f-5750-b98d-a5325ce1a757",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5598b83f-e995-566a-971c-3f703882790f",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25de147a-1ea8-5832-8698-fdb255d3c7f3",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ca1eb0e-981d-50f3-90cf-9f3185c6065f",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d1de607-aeed-5618-9036-e840ce6fff3f",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:655805c8-74a8-5982-9fec-59f4bbf0c61c",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39.tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-messaging@5.3.39.tuxcare.3"
    }
  ]
}