{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b21c7387-b57f-516d-9007-f9faa6af6ccf",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-r2dbc",
      "version": "5.3.39-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7518d76d-75b0-51ee-8ea9-c65b5613f196",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afe97455-36ff-557b-ac43-727d479ca7d5",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42af863b-4c47-5250-84c8-047f879bba70",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb5a45a2-3c7d-5792-b190-750b1262eed3",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b2efd86-10e5-598f-94e9-454870096672",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0660cbc9-5e09-5be3-919e-06a8fe50dc29",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:804ab0ec-08e9-522d-ba0a-1f351805fbc6",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f85aa149-cffd-5525-9144-bfa4dc8136df",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-r2dbc 5.3.39-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78197ece-3d14-5151-b74f-5cc75804dc30",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02962e20-816e-5c42-ac8d-1a29b208aa35",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93dcbf24-a15f-5385-ac36-a81e07c40213",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29da6364-92ce-513b-8eeb-de1dcf55a90c",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df036813-3727-59a6-b237-7535e41513f2",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0e7c748-3b4a-5d6b-8ee8-8f5cfb9361f3",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c73f49b5-5b04-5507-b1ed-235c67bfb672",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5dea8d2-f24d-53ec-a094-6e90a2eaefb3",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9549c752-d507-5684-bb4c-c5a64cde5818",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:442bb3b2-53e4-51de-8ae1-fd8d81d89006",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fd6760a-2603-5a7e-9e5d-3c889db52d8b",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd83fab2-64e1-5bd5-a756-6255adf8fc1e",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09cc19f0-fb3e-5a9f-bbbf-f2c7b3e2db1b",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44de0247-6a27-52a7-b623-879460263118",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2daeedf3-c341-58d7-9238-f8ee90eca39e",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfda52f4-1a50-5bb8-b2e2-feaa1e1d8405",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7bd521a-75e3-57e2-8260-83f00ba3680d",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5244c9ca-a06c-5854-ad00-11cec4cae61c",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ffe274d-2ef9-50c0-babc-ec0ea2939f34",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3364a370-3c09-541e-8734-f7c1cb67ef34",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9691895-c760-5cd2-bddd-fb45f64b27b9",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fa38e66-ee82-501c-a7b9-348ba16bd4cf",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97148653-e8ea-5b05-bd58-6bf9f1ee781d",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40f44745-4304-5972-99ae-b36dd8f187c1",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c85d91c3-4015-5b5d-901d-64038117ddf2",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.39-tuxcare.7"
    }
  ]
}