{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:78865664-f396-55be-b01e-380fcd1633ac",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-oxm",
      "version": "4.3.25.RELEASE-tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a8493e37-4bf7-5383-bed0-6ac642f690ff",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e62f41bc-7e43-5a76-a741-d3a86dae95b8",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-5421 does not affect version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm. not_affected \u2014 CVE-2020-5421 describes an RFD (Reflected File Download) protection bypass via jsessionid path parameters. The target version 4.3.25.RELEASE (released August 2019) is NOT affected because it predates the vulnerability introduction by over a year. The vulnerability was introduced in September 2020 (commit 2f75212eb6 between v4.3.28 and v4.3.29) and fixed in October 2020. The target already has t..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:868ea667-1766-5713-b3c2-97c613c52454",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e6df5f3-f247-5ab4-a406-5c8f16b95228",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-22118 does not affect version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm. not_affected \u2014 Spring Framework 4.3.25.RELEASE is not affected by CVE-2021-22118. This CVE specifically targets WebFlux reactive multipart handlers (DefaultPartHttpMessageReader and SynchronossPartHttpMessageReader) which do not exist in Spring 4.3.x. WebFlux was introduced in Spring Framework 5.0, and version 4.3.25 uses servlet-based multipart handling via Apache Commons FileUpload, which has a fundamentall..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f49e890-f86d-5eb3-83e9-2207deb359cb",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8eaab98-0d4a-5e95-b1e3-6aa2c28383c2",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d65f5b06-c6ac-56f6-8120-d19898bf096d",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18564fc0-f37e-5ff9-836f-d11aeb4603db",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7683adbb-4901-5023-95c5-dfee0c5cf2a6",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c4af90b-d7e6-5702-9956-3da291bdd446",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4569e468-2c8b-5f27-966a-0f74f27fa2e6",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a443f09-4aa7-58c1-87d1-e02056344996",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f33856d5-f5e2-5cd1-b0d4-0833c87094dc",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da835ed4-aaac-5b76-96b2-edd3ec67f59d",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1778c863-3ed4-5577-8fbe-579e70589366",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:def93b17-d281-56a9-a770-3ebf47b79095",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bf7c749-a4eb-5392-b8c7-08aaf5096a52",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce60890f-7ea0-5e0d-868f-b081451cd52f",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm. not_affected \u2014 The target Spring Framework version 4.3.25.RELEASE is not affected by CVE-2024-38820. This CVE addresses a locale-dependent case conversion flaw in the CVE-2022-22968 fix. The target version does not have the CVE-2022-22968 fix and therefore does not perform the toLowerCase() operations that CVE-2024-38820 addresses."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3a9bb93-00a3-5dc8-9047-86fbb4d30196",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:399eef24-591e-50ef-96a6-c8ea454fd62d",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3397936f-c01e-517d-a877-ff91229f1a64",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24d647c1-ee5b-58f4-8bde-353b8edb79b4",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22740 does not affect version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm. not_affected \u2014 Spring Framework 4.3.25.RELEASE is not affected by CVE-2026-22740. The vulnerability exists in WebFlux reactive multipart handling (introduced in Spring 5.0), which is absent from the 4.x series. Version 4.3.x uses servlet-based synchronous multipart processing with explicit cleanup mechanisms that prevent temp file leaks."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fad55a3-81a5-5c02-8928-d1275b0f056e",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08c35dce-90a3-5b57-83f6-b05c28cb1d24",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72afc5c8-5166-5885-9d8c-06b37d361f8d",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f31a60c-9599-5eea-a639-84aea2c022b3",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91a116f2-3ab3-585c-b393-b23dddcffe44",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d313b12-03ee-525a-9b97-4ab7621b81a4",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3cc27bf-88a2-55af-b143-5b2c0d7fd004",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b130ebd4-8dd0-57b5-b35f-eb27db859d88",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:019d1a78-cc0c-5077-938c-f1bd19c5d9a9",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc07f454-8a63-5c01-b2de-a13a27a3e9fa",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c79b89d6-03dc-5ff6-847a-2173d9259e1b",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 4.3.25.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-oxm@4.3.25.RELEASE-tuxcare.1"
    }
  ]
}