{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:dcafc3b9-6b9d-5f3e-85f5-a3d6522c5306",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-orm",
      "version": "5.3.39-tuxcare.13",
      "purl": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f178790c-b1af-5914-8a21-fe039af97d7f",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79174676-2020-5735-a2f8-57a71954e3cf",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.13 of org.springframework:spring-orm. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4b18e8d-dc9f-52cd-b17b-43f2aa2c60a6",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6b705f8-7c1b-5a99-a476-14ec37bd0015",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58e224f2-c670-5167-855f-8e48af350635",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f797e45-8099-5f41-86d8-58dee488e76c",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e09b4109-8575-515b-b412-7b7cf09f6932",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84010667-2ee8-5834-ab94-9d06c1dddefb",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-orm 5.3.39-tuxcare.13."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4415779-eac0-51de-b5e4-6f393b4a9ca6",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65d03417-a725-5d18-810d-6c4dcdfc33a0",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd0b2578-8a15-5b4d-a7b7-7098a5d02e71",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edc9985b-5030-5c33-9c3e-735d301f2ec9",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78fb82d7-4341-571b-94c4-47e6adcf35d9",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3feac6ee-cbf4-5b5c-804f-245267ffbdd8",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f53418d2-579e-5a7a-aa2a-cdb06c5657de",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bacfaede-566f-5f2f-b8d9-b0c5c20509cb",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25dc65c7-c734-5f92-9f08-9224e8dcd275",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83cf9412-5bc5-517b-80da-66c6d3350236",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ded6bf04-3b91-5848-bd44-b95ba067b0ad",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.13 of org.springframework:spring-orm. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb32197c-806a-58b4-a043-389901238501",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5af7941a-741f-5226-ad85-9df837537128",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:244cf5f9-68dc-519a-9e42-3b3d9b60320f",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e3ce8d6-bf76-5cc2-93b3-abd276102a4e",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b338dbcc-24cf-5ccd-84b8-a534e90b5eb7",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3b6203a-e450-5044-9460-51b0652cf2c2",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f320a6ee-9ee0-5e2b-952c-ffe116075412",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:639e7683-c429-5679-85f7-7a8dded6bb47",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff2efd50-8401-5718-9520-301f0c8bad98",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93e5991f-37b1-5726-98b3-c6cc59333b8d",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e8d4bac-01c0-5af9-8d15-1e7d0bab81be",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17ea5008-fbf0-50e7-9d66-a833cbbd9aaa",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c90b1686-947d-52c9-83cf-e3f575e6ebd2",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6674c2df-ca38-52f3-9402-9aacca7cc408",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.13 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-orm@5.3.39-tuxcare.13"
    }
  ]
}