{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c379d74c-91f6-5585-96ce-a896491256c2",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-orm",
      "version": "5.3.29-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:813e1fad-8af5-5c8d-ae76-a3fcc515567a",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88ef4c2b-66b9-59e1-9f7e-4d26d98ed427",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:568a654b-ec21-5b61-a8fd-ff09f53aa70f",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2f1e5c6-f42a-57f0-b2c2-b91e3a83db6f",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3ff136e-19d8-5908-932b-5e343eedf054",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:372bb75b-fc9f-5763-8f10-ba336ec82ae1",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91d9cfef-3da1-5a8f-a419-46d8b5bb0a39",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03a718fc-02b1-539f-a5a7-8c47987c81b9",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:639a910c-34f4-5d11-9dbe-12e0b571f3ed",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcb3bc82-f23c-5ab8-9663-8fc30cf55a51",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2dbebdd-0ae2-5660-9a06-4b2b8b3ed92d",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29e2d197-eff2-5870-94d8-d2585caeeca0",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-orm 5.3.29-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07d55641-3616-5a44-b86f-93db6b9311d5",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:831b6bf0-adf1-5254-b1a9-0ae922d4e49e",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f828f133-cb4b-5992-aad1-1cddf0f726b1",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebd51838-a7bf-5a06-8f03-01481208c3b0",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09d297bb-5d38-5f0b-9d12-0073b5904671",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:085973fe-5b4a-5655-ad73-5fd2268770ed",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d2def95-7744-5e65-989c-7346ddfd478c",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fcdbe9f-ce68-5bbe-9ce6-5bb0ed8a1d22",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df779ac6-3235-5cd4-9d70-0de0dbbb8271",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e3b021f-4e70-5405-b7b9-93053cd03f7e",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83f013f6-49c5-54ad-a1cd-51fca4108f18",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.29-tuxcare.2 of org.springframework:spring-orm. already_fixed \u2014 The target repository (Spring Framework 5.3.29-tuxcare.4) already contains the complete fix for CVE-2026-41840. The fix was applied on 2026-05-19 as part of a TuxCare backport for CVE-2026-22740 (commit bc0026ae70c), which addresses the same multipart request DoS vulnerability with identical code changes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9d99785-9c16-5197-be4b-6e9b03fb2838",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52778be6-fc91-5e84-b1ef-8a111461839d",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17716e35-60dc-56ba-a3f5-f4fa81c80459",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23049080-4c2b-5917-9ef7-9697e004e78e",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dceab999-5988-58c5-9f30-facab39f72bd",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcae26f1-ea4b-538a-ae23-012ef1091e24",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f91bc31f-de50-520a-98f4-c2b9d23d08f0",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a373ff6-00bf-532d-b6a0-3e294eeab4ec",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8adb70ac-2191-5e1e-9b73-603479b7f108",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:386649dd-680f-548f-990e-2d1a2574f4d0",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce654027-f434-55e8-95a8-23349946462a",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdc79b89-6362-5055-af06-9b22f85c855b",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c505acb0-063f-542b-94bd-7d96753b34b5",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a266a94e-40f2-5ce1-bf9f-9ebbddc0d901",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
    }
  ]
}