{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:172222bf-abf3-5b69-b87f-6586be1222f5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-r2dbc",
      "version": "5.3.39-tuxcare.12",
      "purl": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2873b370-f5db-54a5-80e8-ed75bf02cb61",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:247d3e00-0bc5-5f4a-9a20-a523fe73c427",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:968190c0-3511-56a8-9307-bb5af9372688",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d340e4e-6572-50fe-88be-2f85677bb8f4",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7fa832e-25ae-56d9-913a-63db5f93e93f",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ad51c80-cd21-5a72-ab51-db262fde66f2",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71be71d8-ad7d-507d-bedd-e9d5429c174d",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8336a95-9a3b-55ab-ae78-a34767267989",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-r2dbc 5.3.39-tuxcare.12."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4ebe3dd-5ca9-5bd8-af91-b9ad2268a986",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62b16a8a-a259-5125-875a-738299e8b3b3",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f485914-d691-5bb2-86d5-278ff61ea308",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04d0c9ab-6025-5c66-b6d4-e426e0ee2ee7",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:821f3ca4-cca8-5e11-adfc-2eae13a4e632",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b82ca39d-1dea-5979-8351-866bc87af609",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ada0c605-48dc-53e8-ac2d-31b9652f6d92",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8dc0bfa7-b20d-5d4b-806c-762a968f2194",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce091ea8-ee9c-535b-9f80-e5410d72c108",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0154ad8a-7ca0-5c68-be74-5ac5a61e0afd",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b11f5bb0-1cd4-5790-829f-ef8368d07c08",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8dc9cb8-0e60-5168-aa8c-ecf0fd7cc8ec",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49916b13-a152-5e2e-b953-14cd60076013",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8efd46c-dc63-5a7e-bf5b-01e1d0f42c5b",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8b08257-20a8-51d3-b377-5d62ec4d2330",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc48a69d-2af9-57b3-8818-e99b259afec3",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aadefd24-449a-5d45-ace6-a639a15609bc",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b86236f4-c280-5adc-a001-b19507f7ec30",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd73432f-70a6-51f4-8df3-8e8ed7ba2d6b",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2494914f-0f02-5cc4-a6d4-fb801de5be72",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65282a17-4c42-5e92-9442-6bc27be9c27f",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:898580bc-839d-577c-b2b6-1bad946450b2",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93d92d61-dd3b-54ca-8066-f198309e1103",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:262f2aea-9f76-55f7-9b24-1057231d623d",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3504d6f-c69f-5423-9283-1856910a0dc0",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.12 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.12"
    }
  ]
}