{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a49d4229-93b0-5014-8641-1360d078714e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-aspects",
      "version": "5.3.37-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0feaff3d-3131-5467-ad3a-6eaf83433a3c",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5a8f03c-053f-5b13-978a-4933d7754c94",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d137343f-99da-5f2f-9eff-a22295a66f2f",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:816d8644-75d3-5d56-96b2-1e9e772707cd",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7df8e34-08ae-5699-94cc-bb1d61121af0",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32d8cb3c-1bd9-568a-803f-e1acaac6b8b4",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f44f12d4-d53d-5058-b6cc-294bac7dbbdc",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef9d1b9d-ae0e-5a25-b96a-fd8109452319",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4972e697-acfb-5bd6-8e54-adfb56c7aaf9",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93d175ba-b126-5aca-9286-31153a5244be",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5da44541-6c7f-5cb5-aae9-1620f8d765e2",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ba39c32-044a-592f-903b-342f4d22e2e1",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fd35595-f2b6-5aa3-b9c4-d3f19f4c2a4d",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e440e080-79a0-5ea9-9b4f-ea37d50b33f8",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b44342ec-caf0-5104-a0f2-d8f12f588890",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ee182dd-c70f-55ea-9b8b-cac509ca5991",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:391f87ca-7f87-5173-9821-3c7c2a18ff35",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8097088-61da-5c36-92cb-c653dd3bd89a",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eae61f62-fd2c-5f8f-b9fe-a29190b43b0b",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.7 of org.springframework:spring-aspects. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1bddbb7-0401-575c-b966-4a43e6c56ce7",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3caf53a1-ce75-5d65-bf00-280801f48253",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0be450c-d75d-5575-98d0-31d370d1afbd",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2bce1fb-a9d2-5803-a1f5-24112fb5b633",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3d910b6-5545-577d-a112-89efab8129dd",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44cf9ac5-5d8a-5b7f-8b39-e6fcf0615302",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b14325fc-347e-5209-93f7-dfd3c1d2c62b",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d204a53-6102-564e-9577-4e799798c159",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:707c36ca-80db-593d-b4d9-e4a67de273e9",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40a0daef-ad69-5454-aad9-9938229a95e1",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d180f5c3-3a70-5865-98ce-cf304767e202",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dca66444-28fa-5d36-9021-2a425f55d142",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45c869f9-55ce-525e-b7ff-901208b92d91",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09f56c0d-b3c0-5e37-8b4d-77074ef67574",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
    }
  ]
}