{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a3b784d6-8715-5ef7-ac42-3cda5f30f18e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jcl",
      "version": "5.3.37-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d15b6154-54ee-5b89-8a92-d2fd2bf22bb9",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7b59fa6-0884-589c-8ff0-9b14a5aefb88",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b78d2965-22dd-50ab-b3b3-0fd11e463bb6",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8b474e7-f284-56a0-bb9f-d165d5b5e865",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04bb8515-0cb8-5532-adc0-708e1e3b7889",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c59ca01b-e149-5b20-8419-fd24ce691375",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:660d6e60-fe7f-5174-a61c-8731894432fe",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c538dece-433b-5b92-b761-49731e827349",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf7031cf-6395-5ec1-bcce-c6522bccb506",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:782fa1f1-3694-5764-b8ae-b353d7a97101",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5013801c-13b3-552f-aac3-8576ff91d97a",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bec44b6-2a47-57e0-9443-c85107a1cccc",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6493be8d-ac8f-573b-a1cf-904632b79a7c",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a40cb906-3330-5348-a6a6-71f26acfcfce",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b92e8be4-a943-593b-a631-8e3bd6e5e2e1",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6aa6cc9d-d4ff-56a2-81d7-654bb9c54331",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f9a4b65-f923-561c-92f3-14fdd0674375",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d4f06d9-2678-53bf-a8a3-60d7373a8d90",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9dc8416d-139b-52bd-9225-29e82a3b8d2f",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.7 of org.springframework:spring-jcl. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82d7d2fe-e8de-5b6a-9866-715576241bcd",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24b43d7d-5178-545b-862e-4c82569241cb",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35415c04-d2cf-5406-93f6-0e5e3aadc92c",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:730bd858-ffa2-58ff-9c94-5992acae2963",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:085307c6-a642-59d5-a256-44e059dbc55e",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e9b067a-600f-5bdf-8898-fef979866dd9",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:307d5667-9136-5864-b3c0-f1cdbef37661",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bc1c2e9-94ae-53a8-aeda-05a3ea753077",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97b14b1d-0526-5a18-8acb-febff75d4534",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:faa365cf-21bd-5f0d-bf87-b7a2e59c621d",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9180ca2-8aa0-5e95-b556-06ec9910751d",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bf0359b-a098-5caf-a247-340336d77cfe",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:190ee411-5640-5ac2-9be2-bea34a59ee71",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35bd0527-16b2-528f-9f02-b61d1a9a04e8",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.7 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.7"
    }
  ]
}