{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f8ccbe12-2957-5841-b397-6adc5e178bdd",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-oxm",
      "version": "5.3.39-tuxcare.10",
      "purl": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:26c7a34e-98f6-596a-8e2a-025c61d3dc91",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fd08563-ec8f-512e-8a52-2efb751f4796",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.10 of org.springframework:spring-oxm. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46f55087-8cf6-5e0f-a2f1-db9b1064ddd6",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ac04832-c8d4-5ad6-aaf2-c553952e7c17",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19e152b3-51e5-5bc8-bb0b-127b8cc081f1",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7423b5a6-e9d6-527b-be2f-fed6cdbc2159",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f916255-336d-526f-99b3-29389bc3b5de",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54e4f62e-7a5d-51fc-a539-386862bad50c",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-oxm 5.3.39-tuxcare.10."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51f37be8-b820-53a0-b5cf-db226f0ebd8f",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb5149d0-5336-5398-98fc-b92a915568f5",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bffadb3-6fde-5520-baad-b3aeca2e060d",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68e2c52e-21f4-5392-b98d-208e28aa23db",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60edef89-da2a-55aa-8d7b-75834d18c785",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d273567-8ae3-59c6-9ef2-e49c411043a4",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee66bf94-e9b7-5bc7-ba01-bdc51d92ca22",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c74633be-e126-527f-bc6f-48a47296ad59",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a65e2df-0923-5fae-b5e2-6a53b3565914",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b691e8a-8341-5a24-8dee-6c5f3ba2e2ad",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20bb0784-8269-50c1-879f-099380586e1d",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.10 of org.springframework:spring-oxm. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e39379a5-ac60-57f9-9bbe-051013027d5d",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03c57d81-bea6-5e61-8461-ea7954d4d90e",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e048f180-e763-56fe-857b-e75e2855f39b",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8805a15-3205-5a98-809a-09af23a20a0d",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0ba7aa6-ffaa-581f-8da4-e5d658a87685",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84ad7b86-9dc6-5339-a44f-47a0454e77f5",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db2b109b-1134-5118-8a50-aef9af76b61f",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bfb965a-f3a0-52db-b923-a7c2d9a5c2f9",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8db9dbe-c72f-506f-b099-4bf9e2c0abe0",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:471b9b31-abe8-5c9b-8518-2429b3a9cdd0",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98e38f0d-fc47-53fe-9b63-cfd15d783c21",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6df49961-8231-5183-885a-474ce6beb2df",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecb7b6d2-6acd-5e69-8bb9-d613a04ef6e2",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34ad6a4e-5bb2-50d9-9beb-42940a101f7f",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.10 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-oxm@5.3.39-tuxcare.10"
    }
  ]
}