{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a71e6d64-8d3d-51b9-a580-d370f827e8c6",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-messaging",
      "version": "5.3.37-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5149dfdc-1bfc-56f8-89cf-63b0c28e9f22",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef632bd7-87cf-5d4c-885e-bffd2413d3e5",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3247bab7-1541-5773-a81c-4914cf2ddccc",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50be9029-15da-5946-b749-9b1cf4187482",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b46a006d-7a60-58aa-9ded-12c5e6296c43",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33a90381-5284-53c9-a1d5-f4b7aa08b2b1",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:738e5599-482a-5232-8624-2417d9f3f8a0",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fe501e0-0aaa-5215-8b21-475d793405f4",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e5ae19c-bbd9-5a9b-9ab4-faa8ac3a9d78",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:279ef3b2-f588-5f91-8923-875701c82905",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ee62b86-9b10-5399-bbdc-3e9bd8689ef1",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a096442b-4e30-576e-94bf-0113e788b0f8",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d957964-7128-5a8f-ab31-a43d6f4939db",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53dc2dbe-3837-5f92-8b4f-9e6971f3f422",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcf7575b-b633-5b67-aa88-ea525b1e8eb3",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9be51996-625f-54e5-a29d-20b98e84c2be",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1249340-2791-52dc-b261-2f76f6546780",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66154488-19ec-5bdc-975f-0c114c3c14e0",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:103ab8f5-20cb-5972-97ab-c17b33301a56",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.7 of org.springframework:spring-messaging. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8748337b-36a5-59f1-8489-6c1cbc815c49",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a1cf871-0a06-5218-a51f-b426b57de22d",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1802a60-9329-5563-b9f1-543d28101a22",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:988827fa-c887-50bc-a2ee-30da22cb08ca",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e6bddfc-58a1-54aa-b92b-21b096f25740",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89f746ae-2c22-5ef3-ac99-642347e1023d",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88e0f8b7-61c9-5d65-a532-a93d0d9d8613",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d27c8843-cf6f-527e-a7c6-58d4a760d0d4",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:288f0f8e-149c-5b99-9895-a66be76843a6",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c347910a-6023-54a6-84d3-bca753a4314f",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aef87444-1bbd-57a0-9618-b363c9349a21",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c75cc01f-2e0e-5b1b-9763-5b15a4137543",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7c64341-0113-5d4a-9d28-ff95958a9440",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7315281a-a956-5a42-abf7-b5659a7f9b27",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.7 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.7"
    }
  ]
}