{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7193d940-cded-5e56-8725-973af52042ae",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-messaging",
      "version": "5.3.30-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2cc5b99c-b277-5473-aa38-30d8ab2460de",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efd18eea-07b1-5125-87f5-6e5ca574d5f4",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39df197e-da08-5a6a-871d-7e566fe7333d",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92af81e2-7163-53a4-b06c-bd141a1216d8",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1de9b9e7-a9bf-563a-97c6-b11ce51a0171",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:468de41b-ed71-588a-a1e5-97d9cdf319b6",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6a05152-5b04-5a0c-bf43-71874c1a6ec3",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c708cbcb-fbbe-5701-a290-e898587f0a89",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:215c4122-7eab-587c-aacb-990d9d9d2602",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad5d8882-3a76-5c9e-920b-c717b6effb27",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5d77956-e58d-5ecb-a97e-b4f820eba5d6",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2efc8c8f-ae9b-578c-a134-7ab12ee88c1e",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a92d826a-7d13-5f48-8f71-ba505b15af95",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e264a9b4-6f36-5245-a936-7e12a485c220",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a458aaff-16a3-59b5-a649-bb21bd7d6dda",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cc34775-efc7-5871-a871-7385e7d60aba",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:922c4f36-c9f3-5c77-81ef-d4f0ad384a0c",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6de49f8-f04e-59ec-8992-aa6a4dad0003",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00ff037f-bc0b-5818-ad08-3730d9e8ed31",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c67a024-bfeb-5aa9-af93-0e44cc32da92",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f11b0941-fad2-53cf-bf4c-9a292637f06d",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2a565d1-5b41-50be-b6a2-8033c09ed4e9",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.3 of org.springframework:spring-messaging. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0d1ad6b-16f8-57be-9599-015febc27436",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b71f89b-7f40-5bc8-abe9-3183fc52a8e1",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8da67248-cf47-5d59-adb9-43b7f5cc0f41",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34154da6-58ef-5036-b0e5-8018683c61b0",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b38b1cb6-2e59-58d7-9526-77899925a81d",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97da33c4-84c6-5906-8946-1c10faafaa52",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74f3fe5c-6858-531f-aea5-30f9aa7246eb",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cad10d25-6887-5d32-85fb-c7699b29495e",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5818dd27-985c-531a-82d9-d6fcf5256f02",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38e7a9b7-a4be-5c0a-963f-c83bec9b649a",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a12148f0-ca74-5560-b234-bec060eae449",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4dce5bb-5edc-5325-8e22-1aecc302371f",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e82b7f0-adbd-519f-848a-334b719520cd",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76d50596-3e82-5cff-8c24-3a75e84107a4",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.30-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-messaging@5.3.30-tuxcare.3"
    }
  ]
}