{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:681b44db-f629-5fff-88a6-adfdc000f18a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-r2dbc",
      "version": "5.3.31.tuxcare",
      "purl": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ac68c0b9-645a-5ed9-8c98-e90e6db6d9c0",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6dbc47ae-9a0c-5823-8bbc-c9b88bceca93",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b71cac4c-c342-5f2f-85df-ccaeca1cce9c",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a64e608f-b97f-530c-ae55-663f8c189988",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d948cf2-aabf-5b38-8f08-bbde22c370a8",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4f2c76b-4657-5d16-b973-2b0538cb82af",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c085ca8-13aa-5cdb-bdee-14ae4cacad16",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38816 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59735018-49dc-5e84-9d24-8e77e1f943b4",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16098d78-4125-558e-8c10-d4f5a75360fb",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4dd647d8-63c0-5fcb-80c8-53fd82a6c094",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b855cc0-6150-5c4c-bc95-ad47152324c6",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c8c8d7f-e1f2-52ba-ba3b-4158e89d7deb",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-r2dbc 5.3.31.tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40c11721-9ae4-5ef0-9c6d-5ace59f7d5cf",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eeee3888-55b9-5c7d-82e4-2ba88c7963b0",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f036644-841b-5f1e-b0a1-a3a9f606b278",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:831372b8-1e3d-50b7-85e2-468f9f7c4057",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68af5256-c632-5e37-b14f-cce74d55529e",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fbc3d4a-0f37-5e8e-8064-d0182bac2f26",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a7c88fa-b803-515b-9145-4db83f146844",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7c25773-da93-5d2d-bdc1-b38e03505f94",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b70a29d1-89c0-50de-828c-f8ac271426c2",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfac3433-d31f-5371-be86-bb4e5bbcc9f8",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3beea01-fcba-5b7e-a3be-7a76d344cfb5",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31.tuxcare of org.springframework:spring-r2dbc. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:379cb18d-d08b-58f0-93cc-31ca6376d1d8",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:041758f9-d11f-5f55-8504-72605c294ec8",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc6d7672-a043-575d-99a9-3b355c9b8697",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22ed19be-3379-5e1b-88fd-c5cd8131f963",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36d8747e-9d08-54f3-9b76-a4a5582e679f",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75739277-7022-51f7-9ed2-d0d115aa933d",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbccdb89-f272-5c9f-bca6-e058f6c5d297",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef068f4b-07e7-5c00-8a8e-94337e22b1a9",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e65eaee-673b-5901-a92c-c58fb48ccb4a",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23fa3a7d-464b-5e87-8e63-84c9068a7b20",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed2db0bc-e94c-5e1f-99dd-e61f78035e45",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6ad0c7e-bf0e-5cec-89c9-9f655e53a708",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d29f7b67-6b83-5ec8-8017-4cbf7a3616fa",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d395b66-e75a-59f1-9be3-40e65f6975c6",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.31.tuxcare of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.31.tuxcare"
    }
  ]
}