{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ba78cc17-fd7a-5d5f-baba-b2c3d81dd0d0",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-aop",
      "purl": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2",
      "version": "5.3.33-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:75910bcc-9811-5e9e-9ac4-7c825159cb0a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.33-tuxcare.2 of org.springframework:spring-aop and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b4dbf0ef-f7f3-59d0-b2eb-508d986d7db6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:22f501e9-eb99-511b-86d0-00a0eb9107f2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b100da9d-44b6-50f7-b182-43e8f3dd0c10",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:38bc7e58-4719-5747-bac0-cdc741ffa73d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4befb6eb-22af-5411-a40e-bb385c9b7652",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ddd42bbb-be59-5ff6-aa21-43569480d56c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cdc1a9a1-78f4-5e22-8102-31f3a85129db",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6af37e77-60e1-5761-8b84-663d966d3890",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c9f1d016-fbf7-5570-9fe5-e7ed491b136c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:43ab864d-3025-5a8e-9520-e74029e11f40",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:98a6b0f4-dce4-54ce-881c-1444a3035bc0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a1a0172a-4ec0-52f5-9727-6d4a44add49b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4b55e8eb-2de3-5767-b829-72b17436d2a5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:829b43dc-eac4-5b32-9050-2614ef9aa55e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ddc9308e-0682-5b5e-b6e7-a066856e9bcb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:52e0b058-e503-5a0e-9a7c-a813991d370f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bfbfab47-f026-5954-8557-f770606e1640",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d3ed7d5a-974a-52c6-829f-eae1420fd009",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5bd37ea7-0276-533e-a852-d6f5c747bdc7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41840 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0af1de17-67eb-5a59-9f92-2139f998888f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7a5ddf60-97ce-5f38-827e-d517e2d9955e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:38535578-230a-51e3-be85-98b986745649",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e28b1218-9169-58ec-9f34-027521cc683a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9e097344-69d3-5e5a-8774-282363290839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:06650a93-41a1-5e58-8fc5-ee63dcb73458",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dcc9efc8-d94c-5b9a-bc78-5aaf350f813a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2a3cfc0d-e4aa-558a-96cd-6279d0359668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:98d5cfb6-7a9c-530e-a479-608b11a7e156",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7f99913a-ee4a-5064-a3ba-77ceb3c59676",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:637e9748-fcac-542c-9668-c251968e5c3d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:88dd6c5e-7271-5af7-b322-97d788a1e8fc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0016c7eb-a123-5d9d-bd4b-25589bb54f76",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:03336d29-b100-5e86-b063-3a3efa2c3975",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c9caf9e9-2b3e-518b-879c-723fbb79081b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:89d0d602-d29d-5aaa-aa28-f5aad3c83d68",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:93ecafb7-57a3-578d-83ea-f27194aa6aa3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:98a7ebf6-2e2e-5675-8206-6240c8e68eef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:08f6439b-d0b2-5688-ac5c-80e8d0c2bde0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1ee567b8-10d2-56e7-a76d-241ac80f79d4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ce7aaa97-4c45-5b55-8622-5edbdda1b0f1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:87eed952-33b0-5f3d-803c-d8acda99e92a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b4784ebb-c1c4-52f8-85c9-2cf7e5ea6cf0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f02ba0b5-602d-5a52-b544-f2d3b97c8c50",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8779402c-9bb4-5dca-a2fb-5c2e96734137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f0e8215e-9fe5-5c52-b3de-ddd78e29f578",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:70426980-96fb-529c-8827-3b2ddfc1c0a4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dc525e43-ee0d-5ac3-93f1-6775a62c04ff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-aop."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aop@5.3.33-tuxcare.2"
    }
  ]
}