{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c4227421-f6d3-5128-8f90-764647155147",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-aop",
      "version": "5.3.30-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9dcae6b2-ae01-5db5-b314-6952f5466286",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2775f6ad-c2cb-5983-bbd4-a6aad34a94f3",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:555c11cb-13c9-5089-9486-283717c8a59d",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e9a7731-8dbc-54bd-a0c4-a1e939a34905",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8c643aa-024d-53ef-8a89-a89646d76215",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f451c115-a629-57a2-b622-bc25a7cbfc68",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:575ff920-da64-5fd0-a2d9-2a125b2c7bcd",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:913022f5-6cec-5fa4-812e-883b175ff665",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65cfb0f2-1591-56f5-8f62-0ae7da1f6434",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a1b0f68-fb4e-5ec9-aa1f-800f018bfd98",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63ff9a75-2f5e-5e39-a182-35fce417df75",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffdcb3a4-aff8-5cc3-9b14-a2090ceacdd3",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7001b568-6fb4-51d5-adc9-95705b51ab67",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ac1d811-aef2-5f98-a483-90d8eba640c2",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c07c5473-49a1-5804-bb0e-d848ab17d9ee",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3fb0dcb-6499-5c5e-a8ae-fee1203e0014",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5d3f0ee-8596-565a-a960-ddb3ad9202ce",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:981e108c-415d-562f-94e9-d5da4a581852",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:695fa7b0-8bb6-5a50-8eeb-a023a8272ff7",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08677fd9-e301-5213-a965-49850a56c6c9",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:976e3f7d-a836-56ba-ae33-b17ac31345b4",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19bab4a8-1836-5110-901f-04e067959340",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.4 of org.springframework:spring-aop. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c926dc08-7dfc-5312-9d05-be6e60c6504e",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a01a7451-33a1-5aaf-8c9c-ed10dbb4e4f5",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81ebd9bd-4646-59b3-8a96-54069ee2b889",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60c9c39e-3110-5f5f-85e6-83a0561f29bb",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fab14062-90b5-5623-a280-2d4e938bd639",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9f9bbe8-c9b5-5c22-8911-cd12c289b9de",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13fda73e-1d87-5ae7-a54e-5c942c213900",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a462875c-46ec-5831-9844-78739281be70",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2737c4a-947e-5438-b1bf-37ea3220415b",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a502c09-f441-558f-9d92-aa33bb570b64",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b315380-6063-5136-a5c2-b44228cab509",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd79712c-ad81-5f1b-8f2a-e382591ab326",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b5c8bc5-dc2a-5d41-a03f-27a102b593af",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:072939e1-0c7f-538d-98fb-522a2c39d649",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.4"
    }
  ]
}