{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:abb6773b-9443-50e3-a509-c714e6f70883",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-orm",
      "version": "5.3.31-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:afa77de2-08d3-5b85-8f78-01bf69640611",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3d83f5d-b4da-5f16-8cea-cebfbefebfea",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab62023a-61f2-510f-8748-3893fe80363b",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0bef87d-facd-505b-aa10-cdc117378e58",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25623221-7a6c-5427-926e-9df0ecacfe98",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07bdc5eb-588a-5d7b-99c2-f4fbff792768",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e1beaf1-2544-5d57-8cf5-c30a0eba023d",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c80f90f-ad7a-5005-a127-ef781e9d0599",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80a3e38e-cba9-5eff-9b8a-96c329076ce8",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26b723f8-b10c-5075-8eb8-05a861edd3df",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffcd8cc8-c833-5332-8a58-98a3f7fa0a0e",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1b7f786-77d1-5978-9d0e-737f2d0c0d17",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-orm 5.3.31-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddd87a7f-61dc-5030-a716-92f03d4985f4",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecd9ea8b-dfa0-56ef-b18b-decc6fce3dbf",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e845fb8-fb8e-52c0-ae6f-0d44d0386c87",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8576485-02d0-55d8-8951-f49832920fec",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63ee2530-83fd-52c5-a572-71b57a02a42f",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1009cead-37f4-5356-afbe-97fc5cc2b5c6",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc7ed2e3-e05f-54bd-a35c-92587f117767",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc372c6b-fdff-529c-b54d-f9f970000b3c",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69d48217-5a85-566b-b07e-4b9ce1475f0a",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ceade8ff-71cf-595d-8f32-ee7497b1adbb",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2ffc96e-a48c-5d4b-b3b3-833fc0aa03cb",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.5 of org.springframework:spring-orm. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a190ed2f-6316-54bd-a766-168a4c897e30",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b1fedc4-2b24-5e3b-828e-7d558e251f16",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c55cc965-7df4-579e-837b-7e8916a08cf0",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c02bb1b-3b44-5343-afc8-a9b84fe5681d",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e3f5bf0-1655-558e-98a0-35f025c2bdbc",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:035e39aa-748e-5733-a7d6-d44e5141fa04",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8214dda5-b187-58a8-aba3-6bd9a1d1a22c",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8909fe03-cc92-5a03-a9f2-f826724bf4df",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ab34429-3ef3-5938-9377-c8b5bb211f04",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ed26624-659f-504b-a07d-af421d5a096e",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd77e033-20ee-597e-ab77-ba7c8985fd20",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84d4aaea-3170-5d55-a0d8-d608cb44b31d",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87b09d12-43b8-527a-b564-b587120fe4bf",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43cd70c5-ea1c-5110-9227-7ad38e48e161",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.31-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-orm@5.3.31-tuxcare.5"
    }
  ]
}