{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:df4dab4a-5a93-582e-b6e9-c77d49abda8f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-messaging",
      "version": "5.3.37-tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b05a94de-9c5c-5a5f-a31f-769612361961",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bba22ce9-bc6f-531e-bf62-f0845cb1770c",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4e359d8-7c11-5073-b2ba-ce46528cae07",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5895898d-6d17-5084-95e6-bd497622d01b",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c7d300d-e694-59db-be6e-5e20ea9c88ef",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e59c46c-cb69-5c89-a504-26393b57076d",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbb45023-1e10-5e50-9bf2-aff3c0ad95ce",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e93bb7d6-0441-5909-a1f8-84b9c2f99963",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c32c878f-6174-54f4-8c28-74b88bed171f",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b16f23c4-a36f-5a88-bf7b-40bfb654299a",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a92a915-fc75-5b58-9b79-b3c18f1c4967",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f956dac-13cc-569f-bcfb-a4fe451daa2a",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5097e0c5-ea25-5b85-b5e3-de9875eed25c",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0864d2b-44cf-5169-b2c4-db4364b8e24b",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47fa1132-5b8b-5f63-8a4a-34fbffeea87f",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6471eae0-ee50-5e68-813f-6f8f451c7ed2",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc3c55bc-2189-5242-86f9-d23bf801b41c",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb74a3d6-2501-5ad6-99b5-9c3a189af19d",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b92397aa-1eb7-5e6b-8497-b10b9d403f26",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.6 of org.springframework:spring-messaging. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d7760de-c66b-5381-ab03-b26b41dfeca2",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:256c406b-1a94-5b3b-a2d5-591aea3afe3f",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2557544b-b96a-5ce3-ac4a-6f46f2b9980d",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bab14b0-fd72-5b98-9037-e4b61ee50b05",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99b699f9-afb1-558a-8265-20be091eaa2d",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51100f7b-ee17-582b-b71d-bb2ae78f1b09",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82386605-e468-5dc6-b890-7e112ae55bfb",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5edaa242-a0c0-574b-a017-edd9e9876ea5",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85b785c6-1535-556e-86c4-5a99808790d0",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9dc29455-b0ba-5efb-871c-3569dab71495",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e23f319f-1194-5c5d-b8a4-83657ebb1e22",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a37aded-3a43-588b-84ec-3777181cafca",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3b07384-e48c-5117-9611-85aff9ed0d71",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46ea9ae9-4683-51d6-99c2-be0863bb54db",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.6 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.6"
    }
  ]
}