{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:34ed4761-1f4b-58ab-9ed3-8561b93cae99",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jcl",
      "version": "5.3.37-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:03cda9db-e28a-5da4-b928-53ad1501ae8c",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cccf1e4-ee1f-5e2a-b796-7e3397660e9c",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:188d8b67-6140-5764-bd7b-18fcbd9e8b8b",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47efcab2-ad36-5ab8-a91b-65f26b098f7d",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b606625-c2b7-5009-bfb4-5920fd97933f",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41896369-77eb-5812-b54a-9f762e30dcb7",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f477bce3-eff6-5ad2-a614-09bb700de774",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:458dda44-3953-527b-aedc-1cffa8220579",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:655b2682-a28c-5894-99f1-becb1371578f",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1aa187fd-3740-5d37-b77a-0be010a8f8c9",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd685e91-9bea-5290-9763-c63e098d0615",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c2f4252-7b7f-5238-88c9-fc848a330b6a",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ede4f82c-5e32-57a3-8e47-8856f7790817",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf4f15de-3c62-5d9f-b511-76ea00715155",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbd9e6e5-ce4d-584b-949c-2e972310834c",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef7b4b36-6126-5017-b624-7d216b0d933d",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2eb2c3f7-549f-59f5-8c4f-3a23dccbb38a",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b2cb13a-3b19-5ed5-adbe-a69a63b97c33",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:415311a6-cc0b-5185-a4b6-02a0c02347b2",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.5 of org.springframework:spring-jcl. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb4f587e-fa53-53fd-b80a-92785522ab9e",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ef2bc43-5cd7-5df9-91b8-3ed69f9c2a99",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c04e01f-57f7-50dc-8a62-b381e8ca83d4",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5335436-d684-543f-a037-df83512bb89b",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7db2297-61e4-540f-8dbd-e27a09a49c87",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5487d0dd-0ebf-5691-8dea-5abc871c183e",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f2b7eb3-13f0-5e37-bed3-13a0b8202571",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04215238-bc12-5f14-ab0f-fc3bc34e1fc9",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a0b0e03-71f9-5386-9d51-1fa4b9e74836",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80f3df46-7f23-5636-ba8b-c3bdbb841ead",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ba45277-35ec-5570-9fcd-423a451357fa",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb012690-9eb5-5c80-8cb7-6daf43ef524e",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43bc2693-3f3e-5189-815f-bf3cc1fddfea",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cce86f8-091a-5af2-b7df-fa90eb453a0d",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.5"
    }
  ]
}