{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0d19a8a3-f7f8-5515-909a-4c0fba8273ef",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-aspects",
      "version": "5.3.30-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:17fb8d61-99f2-5e8c-9dce-9932d7939573",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:520ea91d-c20d-55be-9a35-e32a606f01f2",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5f3e183-84e0-5ff4-80a1-c1fb40aa57f6",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c303fdcf-7a39-5cf3-920a-6be42c674507",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fe1ebf4-48cf-57cb-a37b-7925ea27b555",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f09157f-bf81-5f80-a937-ea00408e1104",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5472b587-ecff-551b-b421-dbb55770f79a",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d55a4b86-424d-5c97-933c-f7153bd12b76",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1089349-4793-58e9-86a2-b706caae7aa3",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e193b7df-7911-58b3-880e-964de400e86d",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d785509-4592-522e-b10d-4a1e057fdf19",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5149f7fb-af4f-5c1d-b438-969a769646b6",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b22544d-6834-5937-b3e6-3176a0d7d18b",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55060bf7-3212-5b28-a8c4-98ffb4566fd4",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:355f8ef8-b011-5e5d-97f4-fceec0fad2ce",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0f1110b-bfcc-5e32-993c-f87a4c8152fd",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4a2d829-a639-5f2c-9392-2c4678dfa970",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c59844a-2d61-54f5-8fb1-d171cc63f3c1",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e239a38d-6fc9-5329-821d-0fcbb1e34637",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:983efb4e-ed95-5fe5-8bb1-7750cf60f496",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48436b55-476c-59ab-9dba-63867a0fc751",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92b9fbe4-50de-5f48-9b2c-24e487bb7276",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.4 of org.springframework:spring-aspects. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a36a8fc3-1dd5-5dca-bf00-cc1ed5df3990",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f27809b-fb2b-537c-ad9d-74c01a5b1f1c",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab629ecb-5ed0-52ac-ad3b-d89207ec72a7",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55fa6f7c-d83d-501c-ab4c-eda3f17062d4",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0cc55b3-a076-575b-9981-89c29bf10aa7",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7e6204b-e23a-57d7-92b2-66efeec0c705",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bf7c996-1e92-5d2f-be6d-cd71f52c8304",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d61d007-279a-52e1-a85a-1a9caf9ffd48",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcd447b8-826b-5848-8ac1-20586d217fe7",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bdf20af-8b4a-569e-b214-d03fce93d4de",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36f7db59-339f-5713-b94a-e1bd45f8eff0",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61600195-f220-5e5e-ab75-4568044b3ee7",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c48c57c7-a0c1-504c-840f-def4a40064bd",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bb0bc3a-1344-5014-9a28-d72da1a127c3",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.30-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aspects@5.3.30-tuxcare.4"
    }
  ]
}